review-pr

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core behavior matches PR review, and its main network path is official GitHub tooling, so it is not fundamentally incompatible with its purpose. However, it enables autonomous public write actions on GitHub, processes untrusted PR/repo content with parallel agents, and relies partly on unspecified custom MCP/fallback commands, making the overall security posture medium risk rather than benign.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Apr 23, 2026, 03:50 AM
Package URL
pkg:socket/skills-sh/neolabhq%2Fcontext-engineering-kit%2Freview-pr%2F@3c28ad8c8cb4ea965b95321483936607badc3650
Security Audit — socket — review-pr