cto-review

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s GitHub review capabilities largely fit its stated purpose, and its main external CLI (gh) appears official. But it is high-impact because it reads raw local tokens, routes data to unverifiable localhost services, and grants the agent autonomous write/merge authority on GitHub; that footprint is disproportionate for a checklist-style review skill unless tightly sandboxed and explicitly approved.

Confidence: 89%Severity: 79%
Audit Metadata
Analyzed At
Apr 26, 2026, 02:54 AM
Package URL
pkg:socket/skills-sh/fellowship-dev%2Fdogfooded-skills%2Fcto-review%2F@50690a9454499031dd1cc474b6295bbdd219af0d