github-code-review

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The high-level concept of swarm-based PR reviews is sound and aligned with intended automation. However, the webhook handling implementation presents a serious security risk: unvalidated, potentially attacker-controlled input drives shell command execution. To mitigate, remove or restrict execSync usage from webhooks, implement strict input validation, verify webhook signatures, sandbox command execution, and limit the command surface to predefined, whitelisted operations. Improve logging/privacy controls to avoid leaking tokens or PR data in logs.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 25, 2026, 07:40 PM
Package URL
pkg:socket/skills-sh/plurigrid%2Fasi%2Fgithub-code-review%2F@53de9864819ceb00c9cc744d9e4d81af5ba98900