review-loop
Warn
Audited by Socket on Aug 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill’s purpose broadly matches its GitHub/CI capabilities, and its GitHub data flows are mostly official. However, it is still high-risk operationally because it lets the agent consume untrusted PR comments, modify code, and repeatedly commit/push changes, while also invoking an unspecified local script and background agents with unclear trust boundaries.
Confidence: 84%Severity: 71%
Audit Metadata