pr-watch

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s GitHub-only data flow is coherent with its PR-watching purpose, and install trust is relatively low risk because it uses the official gh CLI and GitHub APIs. The main issue is disproportionate autonomy: it continuously monitors untrusted PR comments and can decide to edit code, reply publicly, and possibly push changes in the background without per-action user confirmation.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Mar 21, 2026, 10:22 AM
Package URL
pkg:socket/skills-sh/elie222%2Finbox-zero%2Fpr-watch%2F@84b8d978f26bc60ab666a5ac5533f6b92eb9c2b7