auto-review-loop

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose broadly matches its behavior, and there is no clear malware or deceptive installer pattern. However, it gives an AI agent broad autonomous Bash access, lets external reviewer output steer code and command execution, and repeatedly sends project context to a remote service. The main risk is overbroad autonomous execution and indirect prompt-injection exposure, not confirmed malicious intent.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Mar 15, 2026, 06:42 AM
Package URL
pkg:socket/skills-sh/wanshuiyin%2Fauto-claude-code-research-in-sleep%2Fauto-review-loop%2F@542a4c274a287e5601b13a8f9e9172ce509f0a37