pr-automation
Warn
Audited by Socket on Apr 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
BENIGN for purpose-capability alignment: the GitHub reads/writes, CI checks, comments, labels, rebases, and merges all fit a PR automation skill, and data flows stay within GitHub/local repo tooling. Main risk is not credential theft or exfiltration but autonomous repository actions plus transitive trust in `/pr-review` and `/pr-fix` and repo-controlled Bun tasks.
Confidence: 89%Severity: 68%
Audit Metadata