bmad-os-review-pr

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core purpose is coherent for PR review and its GitHub data flows are proportionate, but it materially increases risk by checking out untrusted PR code, processing untrusted diff content with powerful agent capabilities, and delegating work to another skill. Not malware, but medium security risk due to prompt-injection and transitive-trust exposure.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
Apr 30, 2026, 06:19 PM
Package URL
pkg:socket/skills-sh/bmad-code-org%2Fbmad-utility-skills%2Fbmad-os-review-pr%2F@d8f476d8dba3e872eea154035d3f23bb979936d0