review-pr

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is purpose-aligned for automated GitHub PR review, and its data flows stay on official GitHub tooling/endpoints. However, it grants the agent high-impact autonomous repository actions—including approvals, comments, CI reruns, issue edits, thread resolution, and optional direct pushes—while consuming untrusted PR content, making it a high-risk automation skill despite lacking obvious malware or credential-harvesting behavior.

Confidence: 91%Severity: 74%
Audit Metadata
Analyzed At
Mar 17, 2026, 02:09 PM
Package URL
pkg:socket/skills-sh/max-sixty%2Fworktrunk%2Freview-pr%2F@7c9f4065d5d2ca82b6709fab7a666b4d0d0f0701