github-pull-request-review
Warn
Audited by Socket on Feb 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill describes a coherent, low-risk PR review workflow that uses the gh CLI to collect PR data, compute a quality verdict, and optionally post a review. It avoids executable or exfiltrative behavior in this fragment and relies on standard authenticated GitHub API interactions. To strengthen security posture, add explicit token scope guidance, input validation, and explicit user prompts for any automated posting actions.
Confidence: 75%Severity: 75%
Audit Metadata