gh-pr-review
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Purpose and behavior are broadly aligned for PR review commenting, and the workflow includes a useful safeguard by forbidding final submission. However, the skill's reliance on an unverified gh-review CLI that would use the user's GitHub credentials makes it high risk from a supply-chain and credential-forwarding perspective, so the overall classification is suspicious rather than benign.
Confidence: 86%Severity: 82%
Audit Metadata