pr-review-bot

Warn

Audited by Socket on Sep 8, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The core GitHub review workflow is purpose-aligned and uses official GitHub/Git tooling, but the skill is materially risky because it is designed for unattended public actions, consumes untrusted PR/comment content, and depends on an external pi subagent trust chain before posting under the user's account. No clear credential theft or malware behavior is shown, but the autonomous posting and indirect prompt-injection exposure make this higher than a benign documentation/workflow skill.

Confidence: 88%Severity: 58%
AnomalyLOW
scripts/ledger

The script is intended to create a temporary review ledger and print review-agent instructions. It contains no evident malware or deliberate data theft. However, the user-controlled PR argument is incorporated into a filesystem path without sanitization, allowing path traversal or unintended file creation/overwrite if the script is run with a crafted argument and sufficient permissions. PR numbers should be restricted to digits or otherwise safely sanitized before constructing the path.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Sep 8, 2026, 03:37 PM
Package URL
pkg:socket/skills-sh/skuridin%2Fagent-stuff%2Fpr-review-bot%2F@dca88ae2dc5a59c2085b35f3b86632d28feae847eb0420745498f02792b16630
Security Audit — socket — pr-review-bot