github-code-review

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall, the skill manifest conceptually aligns with an automated, multi-agent PR review system. However, it contains a critical risk pattern in its webhook example: executing shell commands based on unvalidated webhook input (execSync usage). This represents a dangerous remote code execution surface that could be exploited if adopted as-is. While the core toolchain (gh CLI, npx, ruv-swarm) is plausible for legitimate use, the webhook execution example must be removed or heavily sandboxed with strict validation, authentication, and input sanitization before any real deployment. Ensure credentials/tokens are securely scoped and never logged or exposed in outputs.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 10:53 AM
Package URL
pkg:socket/skills-sh/frankxai%2Farcanea%2Fgithub-code-review%2F@09704bf24a7caf4dbe40e1e750b50b75348d5936