address-code-review

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly aligned with code-review remediation and uses official tools, so install trust is acceptable. However, it mixes untrusted external review content with write access and outbound GitHub actions, and it instructs the agent to autonomously reply/resolve threads, creating medium security risk despite a legitimate purpose.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 07:57 AM
Package URL
pkg:socket/skills-sh/maragudk%2Ffabrik%2Faddress-code-review%2F@698b4f6b20c68ee4e85bd5b5d74863db616717f4