looper-pr-takeover
Audited by Socket on Sep 7, 2026
2 alerts found:
AnomalySecuritySUSPICIOUS: the skill’s core behavior matches its stated PR-takeover purpose and mostly uses official GitHub APIs, but it grants an AI agent broad autonomous control over live repository actions and can run unattended via a daemon. Optional Looper installation appears same-org and partially verified, so this is not confirmed malware, but the combination of autonomous merge/push authority and untrusted review-content handling makes it high-impact and risky.
The fragment is a high-impact operational “PR takeover” automation playbook that can bypass human review/merge gates by programmatically resolving review threads and dismissing CHANGES_REQUESTED reviews, then pushing commits and merging (including auto-merge). While the snippet contains no evidence of embedded malware or obfuscation, it is dangerous in any context where it could be executed with unauthorized or overly privileged GitHub credentials. Treat as a serious governance/integrity risk rather than a traditional malware payload.