iterate-pr

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s GitHub/PR capabilities align with its stated purpose and use official tooling, but it is high-risk because it enables fully autonomous recurring repository actions—editing code, committing, pushing, and posting on GitHub—without explicit per-action approval. The main concern is autonomy abuse and exposure to untrusted review/CI content, not malware or credential theft.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
May 8, 2026, 11:58 AM
Package URL
pkg:socket/skills-sh/ReviewStage%2Fstage-cli%2Fiterate-pr%2F@6113990bcfce7c830384f029d05fbd3256aecceb