pr-review
Warn
Audited by Socket on May 9, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose matches its GitHub review capabilities and uses official first-party tools, so there is no strong malware or supply-chain signal. However, it grants an agent high-impact autonomous repository actions after consuming untrusted PR/issue content, making the overall security risk medium-high despite coherent purpose alignment.
Confidence: 90%Severity: 68%
Audit Metadata