babysit-pr

Warn

Audited by Socket on Jul 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN in publisher/dependency trust and data routing, but HIGH RISK operationally: the skill is internally aligned to PR monitoring yet grants the agent broad autonomous authority to push code, rerun workflows, and post reviewer-visible messages after consuming untrusted PR content. Main issue is autonomy and prompt-injection exposure, not malware or hidden exfiltration.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Jul 25, 2026, 04:46 AM
Package URL
pkg:socket/skills-sh/wordbricks%2Fonequery%2Fbabysit-pr%2F@cbc602af5fded0d2f1903733317c2297a47f92f7639de6206b927b33f2024e38
Security Audit — socket — babysit-pr