fix-pr-reviews

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, and its tooling/data flow stay within GitHub and Git, but it gives an agent a high-risk path from untrusted PR/comment content to code modification and automatic commit/push. The main concern is indirect prompt injection plus autonomous external actions, not malware or supply-chain abuse.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
Mar 15, 2026, 06:03 PM
Package URL
pkg:socket/skills-sh/ilamanov%2Fskills%2Ffix-pr-reviews%2F@359b0ee3062e1c83f5e93e2ba4a498fd68e3d424