ah-review-code

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core review workflow is mostly aligned with its stated purpose and uses official GitHub tooling, but risk is elevated by broad delegation to unverified local subskills, persistent storage of diffs/reviews, processing of untrusted diff content, and optional autonomous PR review submission. No clear evidence of malware or credential harvesting appears in this artifact.

Confidence: 84%Severity: 63%
Audit Metadata
Analyzed At
Mar 23, 2026, 06:57 AM
Package URL
pkg:socket/skills-sh/arinhubcom%2Farinhub%2Fah-review-code%2F@ef25f3ab7ef1e560e999c39eca6797d7fa394eaf