pr-risk-analyzerAnalyze GitHub pull requests for security risks and determine if a PR is safe to merge.
Install via ClawdBot CLI:
clawdbot install nerdvana-labs/pr-risk-analyzerGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
POST → https://pr-risk-analyzer.onrender.com/analyze-prCalls external URL not in known-safe list
https://pr-risk-analyzer.onrender.com/analyze-prAI Analysis
The skill sends repository data and potentially access tokens to an undocumented third-party endpoint (pr-risk-analyzer.onrender.com) not controlled by the user or a trusted provider, creating a data exfiltration risk. While the stated purpose is legitimate, the external API is not in a known-safe list and its security practices are unknown, posing a medium risk of credential exposure or data leakage.
Audited Apr 16, 2026 · audit v1.0
Generated Mar 21, 2026
Maintainers of open source repositories use this skill to automatically assess incoming pull requests for security risks like exposed API keys or secrets in code changes. It helps prevent accidental leaks before merging contributions from external developers, ensuring the project's security posture is maintained.
Companies integrate this skill into their CI/CD pipelines to automatically analyze pull requests for risks such as large-scale code modifications or changes to sensitive configuration files. It provides a risk score that can trigger manual reviews or block merges, enhancing deployment safety and compliance.
Freelance developers use this skill to self-audit their pull requests before submitting to clients, checking for issues like hardcoded credentials or risky file alterations. It serves as a quick pre-review tool to improve code quality and reduce client-side security concerns.
In academic settings like coding bootcamps or university courses, instructors employ this skill to evaluate student project pull requests for common security pitfalls. It automates part of the grading process by highlighting risks, allowing focused feedback on secure coding practices.
Offer a free tier for public repositories with limited scans per month, and charge subscription fees for private repositories, advanced features like custom risk rules, or higher scan limits. Revenue is generated through monthly or annual plans targeting small to medium-sized teams.
Sell annual licenses to large organizations for on-premises deployment or dedicated cloud instances, including features like SLA guarantees, custom integrations with internal tools, and priority support. Revenue comes from high-value contracts tailored to enterprise security needs.
Monetize the core analysis API by charging per API call or offering tiered usage packages, allowing other developers to embed the risk analysis into their own applications. Revenue is generated based on usage volume, appealing to integrators and platform builders.
💬 Integration Tip
Ensure the GitHub access token has minimal required permissions (e.g., repo scope for private repos) to enhance security, and test the API with sample PRs to verify response parsing before full deployment.
Scored Apr 19, 2026
Data analysis and visualization. Query databases, generate reports, automate spreadsheets, and turn raw data into clear, actionable insights. Use when (1) yo...
Quick system diagnostics: CPU, memory, disk, uptime
Analyze competitor SEO/GEO: keywords, content, backlinks, AI citations, traffic share gaps. 竞品分析/竞争对手
Professional data visualization using Python (matplotlib, seaborn, plotly). Create publication-quality static charts, statistical visualizations, and interac...
Complete the data analysis tasks delegated by the user.If the code needs to operate on files, please ensure that the file is listed in the `upload_files` par...
Auto-generate structured weekly business reports covering KPIs, accomplishments, blockers, and plans. Save hours of reporting time every week.