worktree-ux-pr

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core workflow is coherent for UX PR automation, and the named developer tools are mostly legitimate. The main risk is the explicit upload of local screenshots to Catbox, a third-party public file host, plus remote-impact actions like force-push and PR commenting; these are proportionate to the task but widen data exposure and operational risk.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Mar 13, 2026, 02:02 PM
Package URL
pkg:socket/skills-sh/different-ai%2Fopenwork-hub%2Fworktree-ux-pr%2F@85e0372743b876a3dd4d414a2e6e98003c8a96ce