pr-loop

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The GitHub-focused capabilities mostly match the stated PR automation purpose, and network flow appears to official GitHub endpoints via the official gh CLI. However, the skill is high risk because it enables autonomous commit/push/PR/reply actions in a polling loop, processes untrusted reviewer comments while retaining write/exec capability, and asks for overly broad permissions with an unsubstantiated TLS rationale. Not confirmed malware, but unsafe automation for an AI agent.

Confidence: 88%Severity: 79%
Audit Metadata
Analyzed At
Mar 21, 2026, 10:22 AM
Package URL
pkg:socket/skills-sh/elie222%2Finbox-zero%2Fpr-loop%2F@802271016d494025ec9722756e141ff200d4c77b