agent-github-pr-manager
Warn
Audited by Socket on Mar 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
This SKILL.md documents a GitHub PR manager that uses the user's gh CLI and git to perform PR lifecycle actions. There is no sign of credential harvesting, remote download/execute, obfuscated code, or references to suspicious external endpoints. The primary risk is operational: if the agent is allowed to act autonomously with merge/admin privileges, it could make destructive or unwanted repository changes. Overall the skill is coherent with its stated purpose and appears benign, but operators should ensure explicit user authorization and limit autonomous merge privileges.
Confidence: 80%Severity: 75%
Audit Metadata