work-with-pr

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core PR automation is coherent, but its footprint is broader than a passive workflow helper because it autonomously pushes code, loops until success, invokes other skills, and merges without explicit final user approval. Data flows mainly stay within GitHub and normal dev tooling, so this is not confirmed malware, but it is a medium-high risk automation skill.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Mar 16, 2026, 04:22 PM
Package URL
pkg:socket/skills-sh/code-yeongyu%2Foh-my-openagent%2Fwork-with-pr%2F@fa03241077f77169bc92d863c3ba95f3bdd743dc