github-pr-fixer

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose mostly matches its capabilities, but it is high-impact. The main concerns are autonomous write actions on GitHub, execution of repo-defined commands from untrusted project context, and automatic installation of a third-party `gh` extension. Data flows stay largely within GitHub and the local repo, so this is not clearly malicious, but it is risky and should require strong user trust and approval boundaries.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
May 8, 2026, 08:53 AM
Package URL
pkg:socket/skills-sh/Satone7%2Fskills%2Fgithub-pr-fixer%2F@4fe7023b021dd46c077d383ac6cbe4769b2e5f46