auto-review
Warn
Audited by Socket on Aug 28, 2026
1 alert found:
AnomalyAnomalyscripts/autoreview
LOWAnomalyLOW
scripts/autoreview
No clear malware or covert supply-chain behavior is present. The code intentionally orchestrates Git, test shells, and external AI review tools. Security review is warranted for deployments where CLI arguments, repository contents, or environment variables are attacker-controlled, especially because --parallel-tests uses shell=True and can execute arbitrary commands. External-engine data disclosure and unrestricted output paths are additional operational risks.
Confidence: 98%Severity: 52%
Audit Metadata