babysit-pr

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core GitHub/CI capabilities align with PR babysitting, and the main tooling is official. Risk comes from third-party data flows (public QR API, optional Diawi), autonomous merge capability, and the missing `monitor.sh` implementation. This looks like a legitimate but medium-risk automation skill rather than malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 23, 2026, 09:58 PM
Package URL
pkg:socket/skills-sh/jonmumm%2Fskills%2Fbabysit-pr%2F@8f3192a065be1583322bf9392a7c40ac6f0529b9