pr-fix

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core capabilities align with a PR-fixing skill and data stays within GitHub/project tooling, but the skill grants an agent high-impact autonomous GitHub actions and executes unpinned package-runner commands. This is not confirmed malware, yet it is a meaningful operational and supply-chain risk for an AI agent.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Apr 11, 2026, 02:16 AM
Package URL
pkg:socket/skills-sh/iOfficeAI%2FAionUi%2Fpr-fix%2F@54556de97888114cf21dbbe961d5c0811b7a4beb