github-pr-triage

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected All findings: [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] This skill is functionally aligned with its stated purpose (exhaustive PR triage with one background task per PR and streaming results). I found no evidence of covert malicious behavior, credential exfiltration, obfuscation, or third-party intermediary data flows. Primary concerns are operational: the enforced 1-task-per-PR model can lead to resource exhaustion, and the auto-close sink is high-impact and must be guarded by explicit confirmation and least-privilege credentials. Recommend auditing the bundled ./scripts/gh_fetch.py and ensuring the operator is required to explicitly approve any auto-close action and that the runtime environment limits parallelism to a safe level. LLM verification: The skill is functionally coherent with its stated purpose: it fetches all open PRs, launches one background task per PR, streams results, and optionally auto-closes PRs. I found no signs of intentional obfuscation, hardcoded credentials, third-party credential exfiltration domains, or encoded payloads. However, the architecture enforces aggressive parallelism (1 task per PR) and includes automated destructive operations (gh pr close) which are high-risk capabilities for a triage skill unless st

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:51 PM
Package URL
pkg:socket/skills-sh/code-yeongyu%2Foh-my-opencode%2Fgithub-pr-triage%2F@328435fe53c6ea218b82f9ec588b3c066f66a005