review-prs

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
prepare-review.py

The fragment appears to be a GitHub PR review orchestration tool, not malware. Its main security-sensitive behavior is use of authenticated gh credentials, including the ability to submit approval reviews, and incorporation of untrusted PR content into downstream subagent prompts. The supplied text also contains substantial syntax and initialization defects that would prevent normal execution. Review the helper scripts and enforce least-privilege GitHub tokens, explicit approval safeguards, and prompt-injection isolation before deployment.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 17, 2026, 03:58 PM
Package URL
pkg:socket/skills-sh/brave%2Fbrave-core%2Freview-prs%2F@e9fd627ead7bbd50ffbe086c1dd42da94879ee546c722cb31a81cdbc9ffe8350
Security Audit — socket — review-prs