pull-request-review

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall, the skill is benign and coherently aligned with its stated purpose. It relies on standard, trusted tooling (GitHub CLI) and operates within a predictable data flow (PR data to a plan). No evident malicious behavior or credential harvesting patterns are present. Potential security/operational risks are limited to authentication requirements and handling of PR data; these are typical for such automation. Recommend ensuring proper access controls and minimizing exposure of PR content in logs.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 10:31 AM
Package URL
pkg:socket/skills-sh/codyswanngt%2Flisa%2Fpull-request-review%2F@8fc696c1bc70571b13aa5f05f9c25ae1068a1c58