aris-auto-review-loop
Warn
Audited by Socket on May 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core purpose is coherent, and the Codex dependency appears official, but the skill gives an agent broad autonomous exec/write powers, direct external model access to repo contents, SSH orchestration, and transitive skill execution. This is a high-risk automation skill rather than confirmed malware.
Confidence: 90%Severity: 78%
Audit Metadata