review-github-pr
Warn
Audited by Socket on May 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is purpose-aligned and mainly uses official GitHub tooling, but it reviews attacker-controlled PR content while also reading code and executing repo-defined validation commands. Its built-in mitigations and explicit confirmation before posting reduce risk, yet the combination of untrusted content plus command execution makes it a medium-risk review skill rather than fully benign.
Confidence: 88%Severity: 58%
Audit Metadata