enter-merge-queue

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is largely coherent with its stated purpose of managing a PR through the merge queue and handling reviews, CI, and post-merge tasks. However, the footprint includes high automation that can alter repository state (rebases, force-pushes, enabling auto-merge) and continuous looping without explicit per-action user confirmation. This creates a suspicious level of operational reach for an agent, especially given the potential for input-driven misbehavior or unintended side effects in complex PR scenarios. Overall verdict: SUSPICIOUS. The capabilities align with the goal of automated PR merge management, but the risk surface from automated, multi-step shell and git operations, loop persistence, and heavy integration with external services warrants caution and closer containment/or explicit human-triggered gates before deployment in a production environment.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 10:13 PM
Package URL
pkg:socket/skills-sh/a2f0%2Ftearleads%2Fenter-merge-queue%2F@90965b76cbc212b204b2759f18beff580c0761d3