review-pr

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned and uses official GitHub tooling, so it does not look malicious. However, it is high-risk as an agent skill because it reads attacker-controlled PR content, can execute repository code, and can autonomously take write actions on GitHub including approvals, comments, thread resolution, dismissals, and optional pushes. Overall classification: SUSPICIOUS due to prompt-injection and autonomy risk, not credential theft or covert exfiltration.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Mar 15, 2026, 12:50 PM
Package URL
pkg:socket/skills-sh/max-sixty%2Fworktrunk%2Freview-pr%2F@9a5cf40fc1a6f2438bd74574c6aefc2cf93dcca0