address-pr-reviews

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is coherent with its stated purpose: it fetches PR reviews/threads, replies to top-level reviews and unresolved threads, and resolves threads, aligning with address/process PR feedback. The data flow is primarily within GitHub (authenticated API calls) and does not indicate external data exfiltration. There is a need to clearly document credential handling (token scopes, storage, and least-privilege) to improve trust. Overall, the footprint is proportionate to the described PR-review automation use-case and does not introduce evident malicious behavior.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 11:39 PM
Package URL
pkg:socket/skills-sh/basecamp%2Fdev-skills%2Faddress-pr-reviews%2F@412955abaec1d8234fc92ac277e160eb2d8c2d2f