follow-up-on-pr

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is purpose-aligned for PR maintenance and uses official Git/GitHub flows, so there is little sign of malware or credential theft. However, it grants an AI agent high-impact autonomous capabilities—executing repo-defined commands, force-pushing branches, and posting/editing PR content based on untrusted PR data—so the operational risk is medium-to-high even though the data flow itself stays within expected GitHub boundaries.

Confidence: 89%Severity: 66%
Audit Metadata
Analyzed At
Apr 23, 2026, 10:35 PM
Package URL
pkg:socket/skills-sh/factory-ai%2Ffactory-plugins%2Ffollow-up-on-pr%2F@e28d5e24de826433849295126e355e9789273bca