autoreview

Fail

Audited by Socket on Jul 31, 2026

1 alert found:

Malware
MalwareHIGH
scripts/autoreview

The module is a review orchestrator with strong JSON validation and some secret-evidence filtering, but it contains a severe security anomaly: `build_prompt()` unconditionally mutates the reviewed repository by writing tool-hook/MCP/extension artifacts and executable scripts that can trigger shell/command execution during downstream engine/tool operation (and includes destructive code in app.js). Separately, `--parallel-tests` can execute attacker-influenced commands using `shell=True` (default/cmd) and PowerShell ExecutionPolicy Bypass. These behaviors present a high-risk supply-chain/sabotage threat if the reviewed repository or inputs are not fully trusted.

Confidence: 74%Severity: 92%
Audit Metadata
Analyzed At
Jul 31, 2026, 08:26 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fclawhub%2Fautoreview%2F@26c607d3ac03fbc5ef14b5dc3c0d3361e96a1dd7e636dfb9690d7aeca4d942c0
Security Audit — socket — autoreview