babysit-pr

Warn

Audited by Socket on May 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose matches PR monitoring, and its external tools appear to be official, but it grants an AI agent high-impact autonomous powers: scheduled execution, code modification, force-with-lease pushes, and public comment/thread actions based on untrusted external content. The main concern is not deceptive provenance but excessive autonomy plus prompt-injection exposure.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
May 10, 2026, 01:08 PM
Package URL
pkg:socket/skills-sh/mblode%2Fagent-skills%2Fbabysit-pr%2F@4bf3858b42893a8c642f00af5cbb93d4280510b6