github-pr-reviewer
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is purpose-aligned and uses official GitHub tooling/endpoints, so it does not look malicious. However, it is a high-impact PR automation skill: it processes untrusted GitHub/repo content, may execute repository scripts, and posts review actions on the user's behalf, making it medium-high risk despite coherent design.
Confidence: 92%Severity: 68%
Audit Metadata