resolve-reviews

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose broadly matches its capabilities, but it gives an agent high-impact autonomous repo and GitHub actions while processing untrusted PR comments through an external CLI package. Main concerns are indirect prompt injection, autonomous push/reply behavior, and moderate supply-chain trust in `agent-reviews`.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
May 5, 2026, 07:03 AM
Package URL
pkg:socket/skills-sh/pbakaus%2Fagent-reviews%2Fresolve-reviews%2F@b030fb4fdb13e1ab6c4447c40e3233efdcdde547