iterate-pr
Warn
Audited by Socket on May 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s GitHub/PR capabilities align with its stated purpose and use official tooling, but it is high-risk because it enables fully autonomous recurring repository actions—editing code, committing, pushing, and posting on GitHub—without explicit per-action approval. The main concern is autonomy abuse and exposure to untrusted review/CI content, not malware or credential theft.
Confidence: 89%Severity: 76%
Audit Metadata