github-pr-reviewer

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is purpose-aligned and uses official GitHub tooling/endpoints, so it does not look malicious. However, it is a high-impact PR automation skill: it processes untrusted GitHub/repo content, may execute repository scripts, and posts review actions on the user's behalf, making it medium-high risk despite coherent design.

Confidence: 92%Severity: 68%
Audit Metadata
Analyzed At
Apr 29, 2026, 10:24 AM
Package URL
pkg:socket/skills-sh/Satone7%2Fskills%2Fgithub-pr-reviewer%2F@5e966a5f7b15a794603340e2948e7ce6c53df329