coderabbit-workflow

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md is a documentation/metadata file describing a CodeRabbit review workflow and references scripts that export comments, run local reviews, and reply to PR threads. The capabilities described are coherent with the stated purpose. No direct malicious behaviors (download-and-execute, credential exfiltration, obfuscated payloads, or references to suspicious domains) are visible in this fragment. The main residual risk is that the actual scripts (not included) could implement network calls or credential handling in insecure ways; those scripts should be reviewed to confirm they call official APIs, do not forward tokens to third-party domains, and require explicit user consent before posting automated replies or committing code with the co-author trailer.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 09:51 AM
Package URL
pkg:socket/skills-sh/bitsoex%2Fbitso-java%2Fcoderabbit-workflow%2F@deb04da201749f3296a3b816529616c23a1a0b41