pr-ship

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s actions largely match its stated PR-shepherding purpose, and data flows stay within GitHub/local tooling, but its footprint is high-impact. Default auto-merge, automatic workflow approval, and execution of branch-defined scripts make it risky for an AI agent even without signs of credential theft or covert exfiltration.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Apr 29, 2026, 05:03 AM
Package URL
pkg:socket/skills-sh/iOfficeAI%2FAionUi%2Fpr-ship%2F@8d4f99b77ddd542f6e3a2588994302a6756366a3
Security Audit — socket — pr-ship