review-pr

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core behavior matches PR review, and its main network path is official GitHub tooling, so it is not fundamentally incompatible with its purpose. However, it enables autonomous public write actions on GitHub, processes untrusted PR/repo content with parallel agents, and relies partly on unspecified custom MCP/fallback commands, making the overall security posture medium risk rather than benign.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Apr 23, 2026, 03:50 AM
Package URL
pkg:socket/skills-sh/neolabhq%2Fcontext-engineering-kit%2Freview-pr%2F@3c28ad8c8cb4ea965b95321483936607badc3650