code-review-assistant

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill's stated purpose and capabilities are coherent and appropriate: it uses the `gh` CLI to fetch PR data and runs local Node scripts to produce human-readable or JSON reviews. There are no direct supply-chain red flags in the provided content (no remote download-and-execute patterns, no unusual network endpoints, no hardcoded secrets). The primary security considerations are operational: the skill requires `gh` authentication and will process whatever is in PRs (including accidental secrets), and integrations (memory-agent, email-agent) could forward sensitive data if used without safeguards. Overall risk is moderate but manageable with prudent operational controls.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:13 AM
Package URL
pkg:socket/skills-sh/winsorllc%2Fupgraded-carnival%2Fcode-review-assistant%2F@24f16364856e6c1bdbeef22ad551c5a9bf13154d