pr-security-review

Warn

Audited by Socket on May 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent and its tooling/data flows stay within official GitHub channels, so it does not look malicious. However, it is high-impact because it combines untrusted PR content ingestion with autonomous write/push/comment/issue actions on a live repo, creating meaningful prompt-injection and action-abuse risk.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
May 9, 2026, 05:44 PM
Package URL
pkg:socket/skills-sh/paulund%2Fai%2Fpr-security-review%2F@afb90d0b102e5498e752d2aee386a3a4f0c79696
Security Audit — socket — pr-security-review