async-pr-review
Warn
Audited by Socket on Mar 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's core behavior matches asynchronous PR review, and the Gemini dependency appears to be an official Google tool rather than an unknown payload. The main risk is proportional but real: untrusted PR content is analyzed by an external LLM service and the workflow can run background checks autonomously, so private code exposure and prompt-injection-style influence are the primary concerns.
Confidence: 80%Severity: 52%
Audit Metadata