review-fix-address-bots
Warn
Audited by Socket on Jul 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
BENIGN in purpose alignment but HIGH RISK operationally. The skill is coherent for PR review/fix automation, yet it grants the agent authority to execute repo code, modify the workspace, push commits, mutate PRs, and react to external reviewer/bot content; this makes it a powerful workflow skill with significant autonomy and prompt-injection exposure, not evident malware.
Confidence: 89%Severity: 76%
Audit Metadata