kf-g-github-pr-review-workflow

Warn

Audited by Socket on Aug 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The GitHub PR workflow purpose mostly matches the described actions, but the skill requires opaque local credential-adjacent bot scripts to perform networked GitHub writes, which is a disproportionate trust dependency. The custom scripts are unverifiable and likely use privileged GitHub App credentials, so the skill carries high security risk even without clear evidence of confirmed malware.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Aug 3, 2026, 11:06 PM
Package URL
pkg:socket/skills-sh/melumuccu%2Fai%2Fkf-g-github-pr-review-workflow%2F@27b608950898fbab306b48e35755abad1d65e04e2d8a519c907ba5c2dff978ab
Security Audit — socket — kf-g-github-pr-review-workflow