resolve-pr-feedback
Warn
Audited by Socket on Apr 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is purpose-aligned and uses official GitHub/Git tooling, so it does not look malicious. However, it is high-impact: it processes untrusted review text and can autonomously edit code, push commits, and post/resolve PR feedback, creating meaningful prompt-injection and autonomous-action risk. Overall classification: SUSPICIOUS due to workflow risk, not credential theft or clear exfiltration.
Confidence: 84%Severity: 68%
Audit Metadata