coderabbit-core-workflow-a
Warn
Audited by Socket on Mar 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the workflow purpose is plausible and mostly aligned with CodeRabbit usage, but trust is weakened by transitive dependency on another skill, mixed/unclear official domains, broad npm-capable bash permission, and unspecified credential handling. Not enough evidence of malware or clear exfiltration beyond the stated code-review service, but the install/auth chain should be verified before use.
Confidence: 84%Severity: 58%
Audit Metadata