pr-review

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is purpose-aligned and uses mostly official tooling, but it is still risky because it instructs the agent to execute build/test commands on untrusted PR code and to take authenticated GitHub actions. This is best classified as SUSPICIOUS/HIGH-VULNERABILITY rather than malicious: no clear credential theft or covert exfiltration, but the review+execute combination is dangerous for an AI agent.

Confidence: 91%Severity: 68%
Audit Metadata
Analyzed At
Mar 16, 2026, 02:10 PM
Package URL
pkg:socket/skills-sh/QwenLM%2Fqwen-code%2Fpr-review%2F@f8354d1c91c43f54becaa75f70d1b5cb9e3d1848