complete-pr

Warn

Audited by Socket on May 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's GitHub-focused capabilities mostly match its purpose, and no direct malicious installer or credential theft appears, but it grants an agent broad autonomous control over repository actions, processes untrusted PR/review content, invokes unreviewed dependent skills, and can trigger a third-party Gemini review flow. Main risk is over-broad automation and transitive trust, not confirmed malware.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
May 16, 2026, 09:34 PM
Package URL
pkg:socket/skills-sh/WillBooster%2Fagent-skills%2Fcomplete-pr%2F@c6dc110fd9311d5753f2a0ff1c672c0b9886567e
Security Audit — socket — complete-pr