oh-pr-workflow

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core capabilities mostly match an OpenHarmony PR workflow, and its main data flows go to official GitCode/OpenHarmony services. However, the skill has meaningful security risk because it can automatically execute a setup script, process untrusted PR content while editing code, and perform impactful repo actions including PR creation, CI-triggering comments, and force-pushes. This looks like a high-privilege automation skill with medium risk rather than confirmed malware.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Apr 9, 2026, 06:58 AM
Package URL
pkg:socket/skills-sh/openharmonyinsight%2Fopenharmony-skills%2Foh-pr-workflow%2F@fa4fc3d039be7e8b8be8f150b25def58a864b707