kf-g-command-do-pr-rev-comment
Warn
Audited by Socket on Aug 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose and GitHub write actions are coherent, but its trusted path is a private local helper script in ~/.agents/credentials plus a referenced setup workflow that were not provided or verifiable. Because an unverifiable executable appears to receive bot credentials for authenticated GitHub actions, the overall security risk is high despite no direct evidence of off-platform exfiltration or confirmed malware.
Confidence: 83%Severity: 82%
Audit Metadata