pr-babysitter

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is coherent with its stated PR-monitoring purpose and uses official service tooling, so it is not malware. However, it is high-impact: it runs autonomously on a schedule, consumes untrusted comments/logs, edits code, pushes commits, and replies/resolves review threads across multiple platforms. Overall this is best classified as SUSPICIOUS due to autonomy and prompt-injection exposure, not deceptive data exfiltration.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
May 17, 2026, 12:10 AM
Package URL
pkg:socket/skills-sh/mblode%2Fagent-skills%2Fpr-babysitter%2F@b0bdb8764800557fe626370c98e744cbbf43586b
Security Audit — socket — pr-babysitter