github-code-review
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose broadly matches GitHub review automation, but its footprint is somewhat overpowered. The main concern is forwarding PR data to an unpinned third-party npm CLI (`ruv-swarm`) and enabling autonomous repo actions plus comment/webhook-triggered execution. Data flows go to GitHub and a same-ecosystem npm package rather than an obvious exfiltration endpoint, so this is not confirmed malware, but it is higher-risk than a purely GitHub-native review skill.
Confidence: 89%Severity: 58%
Audit Metadata