review-github-pr

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is purpose-aligned and mainly uses official GitHub tooling, but it reviews attacker-controlled PR content while also reading code and executing repo-defined validation commands. Its built-in mitigations and explicit confirmation before posting reduce risk, yet the combination of untrusted content plus command execution makes it a medium-risk review skill rather than fully benign.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
May 5, 2026, 10:40 AM
Package URL
pkg:socket/skills-sh/tenequm%2Fskills%2Freview-github-pr%2F@59745de1547275d97def83cda736292e985aeb3a
Security Audit — socket — review-github-pr