auto-review-fix

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is purpose-aligned for automated code review/fixing and shows no clear exfiltration or malware behavior, but it grants an AI agent broad autonomous authority to inspect untrusted code, edit files, run project scripts, and create commits without per-action approval. The main risks are autonomous action and indirect prompt injection from repository content, not supply-chain abuse or credential theft.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Apr 4, 2026, 05:31 PM
Package URL
pkg:socket/skills-sh/stablyai%2Forca%2Fauto-review-fix%2F@79a2129664dd8c3f13f1eb25dc0577a941b91a2a