rhdh-pr-review

Warn

Audited by Socket on May 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s cluster-testing purpose broadly matches its capabilities, but it grants an agent autonomous power to provision and modify a live cluster, trusts adjacent local skills/scripts not verified in the skill text, and deploys CI-derived PR artifacts based on PR comments without an explicit integrity-verification requirement. No clear credential theft or attacker exfiltration path is shown, so this is not confirmed malware, but it is a medium-high risk operational and supply-chain skill.

Confidence: 81%Severity: 67%
Audit Metadata
Analyzed At
May 13, 2026, 08:06 PM
Package URL
pkg:socket/skills-sh/redhat-developer%2Frhdh-skill%2Frhdh-pr-review%2F@c0557b581dd388e997b9e94b52238e44e80a9f41