om-auto-review-pr
Warn
Audited by Socket on Aug 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's capabilities mostly match its PR-automation purpose, but it is a high-impact agent workflow that combines untrusted PR content ingestion with local command execution and autonomous external actions. No clear malware or credential-stealing behavior is shown, yet the autonomy, exec surface, and third-party/transitive trust make it high security risk.
Confidence: 89%Severity: 74%
Audit Metadata