auto-review-loop-llm

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core purpose is coherent, but the skill is over-privileged for a review loop, exports project content to external LLM services, relies on a separately trusted local MCP server, and explicitly directs silent Bash execution without user approval. This looks more like a risky autonomous automation skill than confirmed malware.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
Sep 2, 2026, 10:47 PM
Package URL
pkg:socket/skills-sh/brycewang-stanford%2Fauto-empirical-research-skills%2Fauto-review-loop-llm%2F@b3cdb9cca57c2f5036610ee5c290511924304e659e22377f8d6642e10357b593
Security Audit — socket — auto-review-loop-llm