babysit-pr
Warn
Audited by Socket on Jul 25, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
BENIGN in publisher/dependency trust and data routing, but HIGH RISK operationally: the skill is internally aligned to PR monitoring yet grants the agent broad autonomous authority to push code, rerun workflows, and post reviewer-visible messages after consuming untrusted PR content. Main issue is autonomy and prompt-injection exposure, not malware or hidden exfiltration.
Confidence: 90%Severity: 74%
Audit Metadata