pr-automation

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

BENIGN for purpose-capability alignment: the GitHub reads/writes, CI checks, comments, labels, rebases, and merges all fit a PR automation skill, and data flows stay within GitHub/local repo tooling. Main risk is not credential theft or exfiltration but autonomous repository actions plus transitive trust in `/pr-review` and `/pr-fix` and repo-controlled Bun tasks.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
Apr 8, 2026, 03:31 PM
Package URL
pkg:socket/skills-sh/iOfficeAI%2FAionUi%2Fpr-automation%2F@400ca509cec123aff9324a842392acc946ad4436