pr-resolution

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but it grants a background agent broad autonomous control over code changes, pushes, PR mutations, and CI remediation while acting on untrusted PR content. No clear credential theft or exfiltration is shown, so this is high operational risk rather than confirmed malware.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Apr 15, 2026, 07:15 AM
Package URL
pkg:socket/skills-sh/skinnyandbald%2Ffish-skills%2Fpr-resolution%2F@a6d2eed857d49c8420b108ff43e7cb85a7c9297c