signal-pr
Warn
Audited by Socket on May 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is coherent for GitHub PR automation and uses an official GitHub CLI/data path, so it does not look malicious or like credential harvesting. However, it enables immediate commit/push/PR actions without confirmation and references additional local skill logic not included here, making the overall behavior higher-risk than a passive helper.
Confidence: 87%Severity: 58%
Audit Metadata