drive-pr

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent for PR maintenance, but its footprint is overly autonomous. It lets an agent ingest untrusted comments/logs, modify code, push changes, reply/resolve discussions, and continue acting in a polling loop without fresh user confirmation. No clear malicious exfiltration or installer abuse is present, but the combination of autonomous code execution, remote writes, and external-content-driven decisions makes this a high-risk skill.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Apr 23, 2026, 07:58 AM
Package URL
pkg:socket/skills-sh/rogeriochaves%2Fskills%2Fdrive-pr%2F@9ecbfbb3cda19d9166f6172b38fd4cba0cc75b9a