full-review

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core review function is plausible, but it pairs that with concealed automatic git commits and persistent collection of user-behavior memory. There is no confirmed malware or external exfiltration, yet the hidden autonomous actions and disproportionate memory writing make the skill unsafe and poorly aligned with a normal review-only purpose.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
Apr 7, 2026, 01:28 AM
Package URL
pkg:socket/skills-sh/ilang-ai%2Fautocode%2Ffull-review%2F@cbb47bf94702f2638e62ef0495922eec0c260fcd
Security Audit — socket — full-review