pr-review

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose matches its GitHub review capabilities and uses official first-party tools, so there is no strong malware or supply-chain signal. However, it grants an agent high-impact autonomous repository actions after consuming untrusted PR/issue content, making the overall security risk medium-high despite coherent purpose alignment.

Confidence: 90%Severity: 68%
Audit Metadata
Analyzed At
May 9, 2026, 05:45 PM
Package URL
pkg:socket/skills-sh/paulund%2Fai%2Fpr-review%2F@5f2a8b7eb87172714f00a456744e36140c45b599
Security Audit — socket — pr-review