review-fix-all
Warn
Audited by Socket on Apr 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s review purpose is plausible, but it combines unpinned third-party package execution with autonomous repository actions (edit, issue creation, commit, push) and a recursive loop. This is more a high-impact automation workflow than a narrow review helper, so the overall security risk is high even without clear evidence of malware.
Confidence: 85%Severity: 72%
Audit Metadata