qe-github-code-review

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s overall purpose is coherent for GitHub code review, but its footprint is broader than a passive reviewer. Main concerns are unpinned third-party `npx ruv-swarm` execution, forwarding PR data to that package, webhook examples that act on untrusted PR comments, and autonomous GitHub write actions including approval, pushing fixes, and auto-merge.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
Sep 18, 2026, 06:16 PM
Package URL
pkg:socket/skills-sh/proffesor-for-testing%2Fagentic-qe%2Fqe-github-code-review%2F@9895470068415d5570396e57dad97221c47b641276c701dae046639943150506
Security Audit — socket — qe-github-code-review