github-code-review

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose broadly matches GitHub review automation, but its footprint is somewhat overpowered. The main concern is forwarding PR data to an unpinned third-party npm CLI (`ruv-swarm`) and enabling autonomous repo actions plus comment/webhook-triggered execution. Data flows go to GitHub and a same-ecosystem npm package rather than an obvious exfiltration endpoint, so this is not confirmed malware, but it is higher-risk than a purely GitHub-native review skill.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Sep 15, 2026, 11:37 AM
Package URL
pkg:socket/skills-sh/ruvnet%2Fruflo%2Fgithub-code-review%2F@b48dfbc63ed979d92df4d78afce17f8d5a4e31b4a14a829394fa34689e0525b7
Security Audit — socket — github-code-review