watch-pr

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the GitHub/Greptile data flows are mostly coherent with PR monitoring, but the skill's footprint is broader than passive monitoring. It autonomously consumes external review/log content, edits code, commits, pushes, posts replies, and invokes another skill, making it a medium-high risk automation skill rather than a simple watcher.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Mar 29, 2026, 07:52 AM
Package URL
pkg:socket/skills-sh/meta-pytorch%2Fopenenv%2Fwatch-pr%2F@1310a27ab7a5b062c6a0ed52e0275789ffc2db0f