babysit-pr
Warn
Audited by Socket on May 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose matches PR monitoring, and its external tools appear to be official, but it grants an AI agent high-impact autonomous powers: scheduled execution, code modification, force-with-lease pushes, and public comment/thread actions based on untrusted external content. The main concern is not deceptive provenance but excessive autonomy plus prompt-injection exposure.
Confidence: 84%Severity: 74%
Audit Metadata