autonomous-review

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is purpose-aligned for autonomous PR review, but its footprint is high-risk because it combines untrusted PR/comment input, browser automation, shell execution, token-backed GitHub writes, and explicit approve/merge authority. Install trust is mostly acceptable for official tooling, and there is no clear exfiltration or malware behavior, but the autonomous real-world actions and prompt-injection surface make this a high-security-risk review skill.

Confidence: 88%Severity: 79%
Audit Metadata
Analyzed At
Mar 15, 2026, 11:50 AM
Package URL
pkg:socket/skills-sh/zxkane%2Fautonomous-dev-team%2Fautonomous-review%2F@7b13829e1d8568832ef69fb1f64dc799786568ff