agent-pr-manager

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The pr-manager skill fragment is internally coherent and aligned with its stated purpose of swarm-coordinated PR management, automated reviews, testing, and merging. It relies on standard, trusted tooling (GitHub CLI, npm) and confines data access to PR workflows and local coordination state. No obvious malicious behavior, credential harvesting, or external data exfiltration is evident. Overall risk remains low to moderate (functional automation with multi-agent orchestration), with no identified supply-chain abuse vectors within the provided fragment.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 04:34 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fruflo%2Fagent-pr-manager%2F@0f9857a0d9a7c121257935a3d4b2efb7d4289524