copilot-review-loop
Warn
Audited by Socket on Apr 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core GitHub review-loop behavior is aligned with the stated purpose and data flows stay within GitHub, but the recommended install of an unpinned third-party gh extension from a personal repo is disproportionate trust for a skill that can then act with authenticated GitHub privileges. The skill also enables autonomous commit/push/comment actions, increasing operational risk even without clear malicious intent.
Confidence: 90%Severity: 78%
Audit Metadata