babysit-pr

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s capabilities align with PR babysitting, and its tool choices/data flows are mostly coherent and use official GitHub/Graphite paths. However, it is high risk because it gives an AI agent persistent autonomous authority to read untrusted PR content, modify code, push branches, and post public replies without per-action approval.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:16 PM
Package URL
pkg:socket/skills-sh/neekolas%2Fclaude-skills%2Fbabysit-pr%2F@c7a4b4f08557d637e153798112681e40e6bbd465