pr-guardian
Warn
Audited by Socket on Apr 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose matches PR monitoring/repair, and its external tooling trust chain is mostly coherent (`gh` is official). The main risk is not malware or credential theft but autonomous, repeated code modification/push behavior driven by external CI/review signals, including CodeRabbit comments. This makes it a high-impact orchestration skill that is broader and riskier than a passive monitor.
Confidence: 89%Severity: 72%
Audit Metadata