qodo-pr-resolver

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The overall purpose is coherent for a PR-resolution skill, and the named CLIs are proportionate, but the skill gives external Qodo review text direct influence over code edits and repository actions. The main risk is not obvious malware or credential theft; it is high-impact autonomous modification of code and PR state based on untrusted review content, with missing `providers.md` preventing full install-trust verification.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Mar 29, 2026, 07:41 AM
Package URL
pkg:socket/skills-sh/qwibitai%2Fnanoclaw-skills%2Fqodo-pr-resolver%2F@dbe628e2ef67018de64bdf891f804bc271e611ef