auto-review-loop-minimax
Warn
Audited by Socket on Sep 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The core MiniMax review call is purpose-aligned and uses an official API endpoint, but the skill's real footprint is much broader than external review. It combines broad Bash access, autonomous code changes, SSH-based remote execution, local credential access, and a stealthy 'do it silently' directive, creating meaningful security risk even without clear evidence of malicious intent.
Confidence: 87%Severity: 72%
Audit Metadata