kf-g-command-do-pr-rev-comment

Warn

Audited by Socket on Aug 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and GitHub write actions are coherent, but its trusted path is a private local helper script in ~/.agents/credentials plus a referenced setup workflow that were not provided or verifiable. Because an unverifiable executable appears to receive bot credentials for authenticated GitHub actions, the overall security risk is high despite no direct evidence of off-platform exfiltration or confirmed malware.

Confidence: 83%Severity: 82%
Audit Metadata
Analyzed At
Aug 8, 2026, 09:09 AM
Package URL
pkg:socket/skills-sh/melumuccu%2Fai%2Fkf-g-command-do-pr-rev-comment%2F@88973f6a099ad746e4e7940485010d84e0b3a084d7c424056e873d0ac27344ab
Security Audit — socket — kf-g-command-do-pr-rev-comment