auto-pr-merge

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the tooling and data flow are mostly consistent with GitHub PR automation, but the skill is high-risk because it explicitly removes user approval and performs privileged repository actions, including admin-override merges and autonomous code changes. This is not clear malware or credential theft, but it is an unsafe AI-agent capability with disproportionate authority.

Confidence: 92%Severity: 88%
Audit Metadata
Analyzed At
Apr 4, 2026, 05:31 PM
Package URL
pkg:socket/skills-sh/stablyai%2Forca%2Fauto-pr-merge%2F@2d4220a9cb5cdb7de8568f95956d04e2a8342cf7