auto-review-loop-llm
Warn
Audited by Socket on Sep 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core purpose is coherent, but the skill is over-privileged for a review loop, exports project content to external LLM services, relies on a separately trusted local MCP server, and explicitly directs silent Bash execution without user approval. This looks more like a risky autonomous automation skill than confirmed malware.
Confidence: 85%Severity: 72%
Audit Metadata