worktree-ux-pr
Warn
Audited by Socket on Mar 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core workflow is coherent for UX PR automation, and the named developer tools are mostly legitimate. The main risk is the explicit upload of local screenshots to Catbox, a third-party public file host, plus remote-impact actions like force-push and PR commenting; these are proportionate to the task but widen data exposure and operational risk.
Confidence: 88%Severity: 62%
Audit Metadata