pr-guardian
Warn
Audited by Socket on Mar 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core GitHub polling behavior is coherent and uses official tooling, but the skill crosses into high-autonomy orchestration by proactively invoking itself and repeatedly dispatching code-changing fix skills based on external PR/CI/review content. Main concerns are autonomy and transitive downstream skill risk, not malware or credential theft.
Confidence: 86%Severity: 62%
Audit Metadata