copilot-review-loop

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core GitHub review-loop behavior is aligned with the stated purpose and data flows stay within GitHub, but the recommended install of an unpinned third-party gh extension from a personal repo is disproportionate trust for a skill that can then act with authenticated GitHub privileges. The skill also enables autonomous commit/push/comment actions, increasing operational risk even without clear malicious intent.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Apr 16, 2026, 02:23 AM
Package URL
pkg:socket/skills-sh/xpepper%2Fpr-review-agent-skill%2Fcopilot-review-loop%2F@613999a4320257db1c27df62e543abef2fcd1d03