coderabbit

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The skill is coherent with its stated code-review purpose and appears to use official CodeRabbit infrastructure, but it relies on an unpinned pipe-to-shell installer and forwards code plus authentication to an external CLI/service. This is not fundamentally incompatible with the purpose, yet the install trust and credential/data handling make it medium risk.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Mar 18, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/basher83%2Flunar-claude%2Fcoderabbit%2F@deb1c40070f0715b19439a19d78fa91a85174c5c
Security Audit — socket — coderabbit