pr-review

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core PR-review behavior is legitimate and aligned with its purpose, and the official gh/glab tooling is coherent. The main risk comes from transitive skill dependencies plus processing untrusted PR content while retaining write/action capabilities, which creates meaningful prompt-injection and data-flow uncertainty. No clear credential harvesting or confirmed malicious behavior is present.

Confidence: 85%Severity: 64%
Audit Metadata
Analyzed At
Apr 27, 2026, 01:06 AM
Package URL
pkg:socket/skills-sh/athola%2Fclaude-night-market%2Fpr-review%2F@8db5da87fe0ac93f256456dfc784e351d5837db0