signal-pr

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent for GitHub PR automation and uses an official GitHub CLI/data path, so it does not look malicious or like credential harvesting. However, it enables immediate commit/push/PR actions without confirmation and references additional local skill logic not included here, making the overall behavior higher-risk than a passive helper.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
May 10, 2026, 04:57 PM
Package URL
pkg:socket/skills-sh/mattbaconz%2Fsignal%2Fsignal-pr%2F@424584ca0bdef40f03ca876ed969fcc220bb44a7