github-code-review

Fail

Audited by Socket on Apr 2, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The stated purpose matches GitHub code review automation, but the footprint is high-risk: it combines untrusted external content, third-party CLI/package execution, and autonomous GitHub actions such as commenting, approval, push, and merge. Without stronger provenance for ruv-swarm/claude-flow and tighter guardrails on comment-triggered execution, the skill is not proportionately scoped for safe agent use.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Apr 2, 2026, 07:18 AM
Package URL
pkg:socket/skills-sh/dnyoussef%2Fai-chrome-extension%2Fgithub-code-review%2F@53de9864819ceb00c9cc744d9e4d81af5ba98900