review-fix-address-bots
Warn
Audited by Socket on Aug 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's overall purpose is coherent, but its footprint is high-risk: it combines external reviewer/bot input with local execution, code mutation, and Git/PR actions. The biggest concerns are indirect prompt-injection exposure and autonomous repository mutations, plus executing an opaque repo-local helper and repo-native scripts.
Confidence: 86%Severity: 72%
Audit Metadata