solo-review
Warn
Audited by Socket on Apr 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core review/testing purpose is legitimate, and network/data flows mostly align with developer tooling, but the skill overreaches by autonomously editing docs, committing changes, and emitting pipeline control signals. The biggest risk is broad Bash/write authority combined with executing project commands from potentially untrusted repo context.
Confidence: 88%Severity: 62%
Audit Metadata