coderabbit-core-workflow-a

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the workflow purpose is plausible and mostly aligned with CodeRabbit usage, but trust is weakened by transitive dependency on another skill, mixed/unclear official domains, broad npm-capable bash permission, and unspecified credential handling. Not enough evidence of malware or clear exfiltration beyond the stated code-review service, but the install/auth chain should be verified before use.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 24, 2026, 05:51 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fcoderabbit-core-workflow-a%2F@e537679414e5c92e5ad1ad12b15d6d81a8571700