handle-pr-feedback

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill's capabilities mostly match its stated GitHub PR workflow and its network path appears to stay within official GitHub tooling, so install/data-flow trust is relatively coherent. However, it gives an AI agent high-impact autonomous abilities to interpret untrusted PR comments, modify code, push commits, and post responses without explicit per-action confirmation, making it risky despite not looking malicious.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Mar 21, 2026, 02:39 AM
Package URL
pkg:socket/skills-sh/hifisaputra%2Fskills%2Fhandle-pr-feedback%2F@cdda91b12852c58acfdbe0a781b10952bb3c3363