autoreview

Warn

Audited by Socket on May 29, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/test-review-harness

This module is a security review harness that generates a “malicious” Node.js fixture containing clear high-risk behavior (execSync-based destructive rm -rf using interpolated input and direct password disclosure). The bash harness itself only writes the fixture and runs a local reviewer, but because the package includes/produces destructive and credential-leaking code, it poses a moderate-to-high supply-chain/security risk if misexecuted or distributed without strict controls.

Confidence: 74%Severity: 62%
Audit Metadata
Analyzed At
May 29, 2026, 09:03 AM
Package URL
pkg:socket/skills-sh/BjornMelin%2Fdev-skills%2Fautoreview%2F@e6dc05dec7edcb0f0672eec39b2e66d442ae2bc6
Security Audit — socket — autoreview