create-pr

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This skill is mostly aligned with its stated PR-automation purpose and uses official GitHub flows, so it does not look malicious. Risk is medium because it can autonomously commit, push, create PRs, schedule jobs, and install/invoke an external plugin/skill, creating a transitive trust and execution path beyond simple PR creation.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 15, 2026, 12:25 PM
Package URL
pkg:socket/skills-sh/yonatangross%2Forchestkit%2Fcreate-pr%2F@f8bae11edca88d76d3eb0c070c171cf6db32c97c