workflow-review-changes
Warn
Audited by Socket on May 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent for code-review automation, and it shows no external installer or credential-harvesting path. Risk comes from broad autonomous orchestration, recursive delegation to many other unverified slash-workflows, and prompt-injection exposure from reviewing attacker-controlled repo content before taking write actions.
Confidence: 82%Severity: 59%
Audit Metadata