review-loop

Warn

Audited by Socket on Aug 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s purpose broadly matches its GitHub/CI capabilities, and its GitHub data flows are mostly official. However, it is still high-risk operationally because it lets the agent consume untrusted PR comments, modify code, and repeatedly commit/push changes, while also invoking an unspecified local script and background agents with unclear trust boundaries.

Confidence: 84%Severity: 71%
Audit Metadata
Analyzed At
Aug 11, 2026, 05:09 PM
Package URL
pkg:socket/skills-sh/cor-incorporated%2Fclaude-code-skills%2Freview-loop%2F@f2a790c3e99f9dfab6eaf5f44fe4eb027fe49592bfbf41e7aae73921e9eccbf0
Security Audit — socket — review-loop