pr-review-canvas

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The chosen report is coherent and appropriate: it describes a low-risk, developer-focused tool for generating an interactive PR review HTML from GitHub data. The workflow is plausible, relies on established tooling, and includes defensive steps for embedding JSON safely. Primary recommendations include adding explicit cleanup steps for /tmp artifacts, ensuring the final HTML is access-controlled when containing potentially sensitive PR data, and providing a formal threat model for local-host usage. Overall risk remains low-to-moderate given controlled environments.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 10:32 AM
Package URL
pkg:socket/skills-sh/cursor%2Fplugins%2Fpr-review-canvas%2F@44daadad1fe53ccd3a2773e87879965c1640ab71