pr-publish-agent

Fail

Audited by Socket on Feb 21, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No explicit malicious or obfuscated code patterns are present. The module describes an automation that legitimately performs remote operations (git push, PR creation, issue comments/status changes) and therefore requires careful handling of credentials and operational controls. Key recommendations: run in trusted environments, use least-privilege identities for gh/MCP operations, validate MCP mappings, add explicit human-approval or dry-run modes before applying remote changes, and add safeguards to prevent accidental leakage in PR bodies or automated CI triggers.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 21, 2026, 10:47 AM
Package URL
pkg:socket/skills-sh/vishal2457%2FopenIT%2Fpr-publish-agent%2F@3b40af10e9cf3faa5c66059e44e7079488ddb6ef