review
Warn
Audited by Socket on Jul 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill is purpose-aligned and uses official GitHub/NuGet endpoints, so it is not malicious. However, it is a medium-high risk automation skill because it processes untrusted PR content and can publicly approve, request changes, and post comments without explicit user confirmation, with added transitive trust in `/knowledge-sync`.
Confidence: 86%Severity: 72%
Audit Metadata