pr-guardian

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core GitHub polling behavior is coherent and uses official tooling, but the skill crosses into high-autonomy orchestration by proactively invoking itself and repeatedly dispatching code-changing fix skills based on external PR/CI/review content. Main concerns are autonomy and transitive downstream skill risk, not malware or credential theft.

Confidence: 86%Severity: 62%
Audit Metadata
Analyzed At
Mar 26, 2026, 05:37 PM
Package URL
pkg:socket/skills-sh/s-hiraoku%2Fsynapse-a2a%2Fpr-guardian%2F@55ac99134141cc2067dc7896b48ca3c99bcb5706