post-pr-for-review
Automates posting pull requests for review in Slack, ensuring proper notifications and checks before submission.
Install this skill
or
90/100
Security score
The post-pr-for-review skill was audited on May 28, 2026 and we found 2 security issues across 1 threat category. Review the findings below before installing.
Categories Tested
Security Issues
medium line 146
Webhook reference - potential data exfiltration
SourceSKILL.md
| 146 | - **MCP not connected** → ask user to connect Slack MCP. Do NOT fall back to webhooks (wrong identity). |
medium line 161
Webhook reference - potential data exfiltration
SourceSKILL.md
| 161 | Slack MCP posts as the human user, preserving thread-reply notifications and attribution — right etiquette for review channels. Webhook posting (used by `audit-request-slack-relay`) is intentionally N |
Scanned on May 28, 2026
View Security Dashboard