debate-review
Audited by Socket on Aug 25, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: the core purpose is coherent for PR/MR review and data flows appear to use official GitHub/GitLab CLIs, but the skill depends on third-party delegate skills and encourages transitive skill installation. Its ability to post comments from the user's account is proportionate to purpose yet still a meaningful real-world action risk.
No direct malicious payload is visible in this fragment; however, it performs dynamic discovery and execution of locally found delegate scripts (including via an environment-controlled directory) and reads untrusted JSON results produced by that executed code. The primary risk is supply-chain/local-plugin execution: if an attacker can influence DELEGATE_SKILLS_DIR or the searched skill directories or replace relay.mjs/config.mjs, arbitrary code execution is achievable. Additional issues are mainly robustness/trust-boundary related (brittle JSON extraction; probe execution via --help; limited validation of plugin selection beyond path existence).