autofix
Warn
Audited by Socket on Mar 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core GitHub tooling and data flow are mostly aligned with the stated purpose, but the skill's defining behavior is unsafe: it instructs the agent to execute CodeRabbit PR comment prompts as direct instructions, then edit code and optionally commit/push/post results. This creates a high indirect prompt-injection risk and meaningful autonomy risk even without obvious credential theft or malicious install behavior.
Confidence: 90%Severity: 79%
Audit Metadata