autoreview
Fail
Audited by Socket on Jul 31, 2026
1 alert found:
MalwareMalwarescripts/autoreview
HIGHMalwareHIGH
scripts/autoreview
The module is a review orchestrator with strong JSON validation and some secret-evidence filtering, but it contains a severe security anomaly: `build_prompt()` unconditionally mutates the reviewed repository by writing tool-hook/MCP/extension artifacts and executable scripts that can trigger shell/command execution during downstream engine/tool operation (and includes destructive code in app.js). Separately, `--parallel-tests` can execute attacker-influenced commands using `shell=True` (default/cmd) and PowerShell ExecutionPolicy Bypass. These behaviors present a high-risk supply-chain/sabotage threat if the reviewed repository or inputs are not fully trusted.
Confidence: 74%Severity: 92%
Audit Metadata