ship-pr

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

BENIGN overall for its stated PR-shipping purpose, but with a notable high-risk optional automation path: the compozy/CodeRabbit review loop can consume external review input and then auto-commit and auto-push changes. No obvious credential harvesting, hidden exfiltration, or suspicious installer behavior appears in the provided skill text.

Confidence: 84%Severity: 66%
Audit Metadata
Analyzed At
May 12, 2026, 04:37 PM
Package URL
pkg:socket/skills-sh/pedronauck%2Fskills%2Fship-pr%2F@48ba57c95f82bf443b139095c9d1a1fca5466da2