pr-review

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s review/comment/merge behavior is mostly aligned with its stated purpose, and GitHub data flows appear direct to official endpoints. Risk is elevated because it autonomously performs impactful actions, processes untrusted PR content while executing local commands, and delegates core behavior to an only weakly verifiable `kspec` workflow.

Confidence: 84%Severity: 81%
Audit Metadata
Analyzed At
Mar 16, 2026, 01:24 AM
Package URL
pkg:socket/skills-sh/kynetic-ai%2Fkynetic-spec%2Fpr-review%2F@b39768476948dd8f15573a1158e53127d416bd64