ai-code-review
Warn
Audited by Socket on Aug 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core review behavior is coherent, but the skill adds autonomous filesystem writes and automatic git commit/push to a separate vault repo. No installer or credential-harvesting signs appear, yet the outbound sync to an unchecked configured remote and the combination of untrusted diff ingestion with write/exec capabilities make it medium risk rather than benign.
Confidence: 86%Severity: 58%
Audit Metadata