work-with-pr

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The workflow is mostly aligned to its stated PR-lifecycle purpose and uses official GitHub/git/Bun tooling, but it grants an AI agent broad autonomous repository powers: unbounded fix/push loops, processing untrusted external review content, transitive skill loading, and automatic merge/delete actions. Main risk is high operational autonomy and prompt-injection exposure, not confirmed malware or credential theft.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
Mar 27, 2026, 08:31 AM
Package URL
pkg:socket/skills-sh/code-yeongyu%2Foh-my-openagent%2Fwork-with-pr%2F@7ebcd3681dbd3e3f54e249246fa80730283e3868