qe-github-code-review
Warn
Audited by Socket on Sep 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s overall purpose is coherent for GitHub code review, but its footprint is broader than a passive reviewer. Main concerns are unpinned third-party `npx ruv-swarm` execution, forwarding PR data to that package, webhook examples that act on untrusted PR comments, and autonomous GitHub write actions including approval, pushing fixes, and auto-merge.
Confidence: 83%Severity: 58%
Audit Metadata