pr-miner

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s stated purpose is coherent, and its visible network flow targets official GitHub services. However, the critical mining path depends on opaque local Python executables with no verifiable provenance while using repo-scoped GitHub credentials, making this high security risk and suspicious rather than clearly malicious.

Confidence: 84%Severity: 84%
Audit Metadata
Analyzed At
Mar 29, 2026, 05:30 PM
Package URL
pkg:socket/skills-sh/notque%2Fclaude-code-toolkit%2Fpr-miner%2F@9496408d2ff0e658f78d66ed5ea8e3fda8daf45c