github-pull-request-review

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill describes a coherent, low-risk PR review workflow that uses the gh CLI to collect PR data, compute a quality verdict, and optionally post a review. It avoids executable or exfiltrative behavior in this fragment and relies on standard authenticated GitHub API interactions. To strengthen security posture, add explicit token scope guidance, input validation, and explicit user prompts for any automated posting actions.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 12:30 PM
Package URL
pkg:socket/skills-sh/talendar%2Fagent-skills%2Fgithub-pull-request-review%2F@611951fd132d0b7ae0c1a6dba453f3f5df1ba9af