github-pr-reviewer

Warn

Audited by Socket on Jun 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is largely coherent with its stated purpose and uses official GitHub endpoints, but it enables autonomous cron-driven GitHub commenting, forwards sensitive repo context into OpenHands conversations, and processes untrusted PR/discussion content. This looks more like a high-risk automation workflow than malware; main concerns are autonomy and data-handling scope, not deceptive installation or credential theft.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Jun 24, 2026, 08:21 AM
Package URL
pkg:socket/skills-sh/openhands%2Fskills%2Fgithub-pr-reviewer%2F@278fc4f832b33de5ae34deb8f1ae159120ba69d9bb1d5fe764cb416f56a2245e
Security Audit — socket — github-pr-reviewer