github-code-review

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The fragment contains a high-risk pattern: a webhook-handler that executes shell commands derived from untrusted webhook payloads. While the skill aims to orchestrate multi-agent code reviews via swarm tooling, the presence of direct execSync-based command execution from webhook data represents a severe command-injection and remote-control risk. This content is not coherently aligned with safe, production-grade supply-chain tooling and should be removed or heavily sanitized with proper authentication, input validation, sandboxing, and least-privilege handling. Overall, the content exhibits suspicious to high-risk data-flow patterns that could enable remote code execution and unintended actions if adopted as-is. The rest of the document, which focuses on swarm orchestration and PR management, is otherwise legitimate in isolation but gains risk due to the insecure webhook sample.

Confidence: 68%Severity: 72%
Audit Metadata
Analyzed At
Mar 4, 2026, 07:39 PM
Package URL
pkg:socket/skills-sh/ruvnet%2FRuView%2Fgithub-code-review%2F@53de9864819ceb00c9cc744d9e4d81af5ba98900