when-reviewing-pull-request-orchestrate-comprehensive-code-review

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose broadly matches code review orchestration, but its footprint is high-risk because it executes untrusted repository code, relies on an unpinned third-party orchestration package, and can autonomously modify or merge PRs. The main concern is unsafe automation and trust expansion rather than confirmed malware.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
Apr 2, 2026, 07:21 AM
Package URL
pkg:socket/skills-sh/dnyoussef%2Fai-chrome-extension%2Fwhen-reviewing-pull-request-orchestrate-comprehensive-code-review%2F@63d050c2bd6b81c6724cdd299d13254a27b935b5
Security Audit — socket — when-reviewing-pull-request-orchestrate-comprehensive-code-review