pr-testing

Warn

Audited by Socket on May 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The overall purpose is coherent for a PR-testing skill, and the Microsoft/Aspire install sources are plausibly official. However, the skill has a serious integrity flaw: it derives a shell install command from PR comments and executes it unchanged, creating a direct untrusted-content-to-shell path. Running PR-built binaries is in scope for testing, but combined with comment-driven command execution and raw GitHub installers, the skill carries medium-high security risk.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
May 5, 2026, 06:36 PM
Package URL
pkg:socket/skills-sh/microsoft%2Faspire%2Fpr-testing%2F@abea17e19b22e104d15a6cc347c088e3447371cb