jb-autoreview

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/autoreview

No clear evidence of intentional malicious payload (no direct credential theft, persistence, or reverse-shell behavior). The biggest security risk in this fragment is operational: it executes external binaries resolved via PATH/user-provided bin names and can run arbitrary host commands via --parallel-tests (shell=True / PowerShell ExecutionPolicy Bypass), and it bundles and forwards potentially sensitive repository contents (including untracked files) to external AI engines, potentially with web-fetch capabilities. These behaviors should be reviewed/locked down in supply-chain and CI contexts, especially for attacker-controlled CLI/environment inputs.

Confidence: 64%Severity: 52%
Audit Metadata
Analyzed At
Jul 31, 2026, 09:02 PM
Package URL
pkg:socket/skills-sh/bjesuiter%2Fskills%2Fjb-autoreview%2F@240a92a8d47ed26e905b28d7517e67cdf86faa37b7b7c58336227989ed3d6ba4
Security Audit — socket — jb-autoreview