implement-suggestion
Warn
Audited by Socket on May 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's core purpose is coherent for PR review automation, and its GitHub/git access is proportionate, but it gives an AI workflow the ability to turn untrusted PR comments into code edits, commits, and pushes. The main risk is indirect prompt injection combined with autonomous repository actions, not overt malware or credential theft.
Confidence: 89%Severity: 72%
Audit Metadata