pr-ship
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s actions largely match its stated PR-shepherding purpose, and data flows stay within GitHub/local tooling, but its footprint is high-impact. Default auto-merge, automatic workflow approval, and execution of branch-defined scripts make it risky for an AI agent even without signs of credential theft or covert exfiltration.
Confidence: 85%Severity: 74%
Audit Metadata