coderabbit-migration-deep-dive

Warn

Audited by Socket on May 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the overall migration purpose is coherent, but the actual install path is inconsistent with the official CodeRabbit evidence provided. The skill also grants an AI agent the ability to make live kubectl and traffic-shifting changes, which is high-impact operational scope for a guide. No clear credential theft or exfiltration is shown, so this is not confirmed malware, but it carries medium security risk due to install-trust mismatch and autonomous infrastructure actions.

Confidence: 85%Severity: 57%
Audit Metadata
Analyzed At
May 20, 2026, 01:12 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fcoderabbit-migration-deep-dive%2F@0d414e8c2321899cc8e26f86844843a447dfc393
Security Audit — socket — coderabbit-migration-deep-dive