classify-review
Warn
Audited by Socket on Aug 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Mostly coherent with its stated PR-comment false-positive filtering purpose. Main risk is the required but unreviewed local updater script plus moderate prompt-injection exposure from sending untrusted review comments to a subagent that can trigger a Bash-driven state update; data flow otherwise appears proportionate and directed to official Anthropic services.
Confidence: 83%Severity: 72%
Audit Metadata