update-pr

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated purpose is legitimate and its repo/GitHub access is proportionate, but it achieves this by executing an unpinned third-party npm package via bunx @latest. That creates a meaningful supply-chain and possible credential-forwarding risk because remote code receives PR content and may operate with GitHub auth, even though no explicit malicious endpoint or confirmed exfiltration is shown.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Apr 23, 2026, 06:14 PM
Package URL
pkg:socket/skills-sh/willbooster%2Fagent-skills%2Fupdate-pr%2F@379402e439cde875078961f95ae74e40262f8352
Security Audit — socket — update-pr