implement-suggestion

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's core purpose is coherent for PR review automation, and its GitHub/git access is proportionate, but it gives an AI workflow the ability to turn untrusted PR comments into code edits, commits, and pushes. The main risk is indirect prompt injection combined with autonomous repository actions, not overt malware or credential theft.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
May 17, 2026, 04:55 AM
Package URL
pkg:socket/skills-sh/mthines%2Fagent-skills%2Fimplement-suggestion%2F@1a20366c4b5b55d356e29236cd40c6f629ce1df2
Security Audit — socket — implement-suggestion