read-only-gh-pr-review

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill presents a coherent, read-only PR review workflow that aligns with its stated purpose. It relies on the GitHub CLI in a read-only context and local repository analysis, avoiding write actions or credential harvesting. Trust sources are official tooling (gh CLI) and a documented read-only wrapper. Data flows stay within the user's environment and GitHub API, with no mutation or exfiltration mechanisms described. Overall risk is low to moderate (benign), with attention to ensuring the read-only wrapper cannot be bypassed and that logs do not inadvertently leak sensitive PR data.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 10:01 AM
Package URL
pkg:socket/skills-sh/jawwadfirdousi%2Fagent-skills%2Fread-only-gh-pr-review%2F@73c4dc8af008a48b40c180c3fda33baa079ee420