auto-review-loop-minimax

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The core MiniMax review call is purpose-aligned and uses an official API endpoint, but the skill's real footprint is much broader than external review. It combines broad Bash access, autonomous code changes, SSH-based remote execution, local credential access, and a stealthy 'do it silently' directive, creating meaningful security risk even without clear evidence of malicious intent.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Sep 2, 2026, 10:47 PM
Package URL
pkg:socket/skills-sh/brycewang-stanford%2Fauto-empirical-research-skills%2Fauto-review-loop-minimax%2F@ca01fef80754189b14ba3151e921ca3744dd88313e45594a35b27018230e6767
Security Audit — socket — auto-review-loop-minimax