custom-codereview-guide

Warn

Audited by Socket on Jun 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is purpose-aligned and uses official GitHub tooling, with no obvious credential theft or third-party routing. The main risk is autonomous approval of PRs via the GitHub API based on simplified matching logic, which can cause unintended repository actions if misapplied.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Jun 20, 2026, 02:39 AM
Package URL
pkg:socket/skills-sh/OpenHands%2FOpenHands-CLI%2Fcustom-codereview-guide%2F@e92878bbf6338113bf595ca8dc0ab68dd968d080deaa1e3316d3c1eb1170f8e9
Security Audit — socket — custom-codereview-guide