pull-request

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

No direct malicious code or obfuscation is present in this Skill instruction file. The file describes a coherent automation for creating/updating GitHub pull requests and the requested capabilities align with the stated purpose. However, there are security/usability risks: it explicitly forbids checking repository status or prompting to push, which can lead to accidental PRs created/updated from an unexpected repository state. The actual execution and any network or credential use is delegated to the git-operations-specialist skill — that delegated component must be audited because it will run gh commands and access credentials. Overall: not malicious, but moderate operational risk due to aggressive constraints and reliance on a delegated executor.

Confidence: 80%Severity: 45%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:05 AM
Package URL
pkg:socket/skills-sh/gendosu%2Fagent-skills%2Fpull-request%2F@b838b85a8d7119b284488faa3267f45710120327