jules-review

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the GitHub posting behavior is aligned with the skill’s purpose, and gh itself is an official dependency, but the skill’s core review path depends on an unverified /council skill that receives full PR context and diff data. Combined with untrusted PR-content processing and the ability to post public reviews/comments, this creates medium risk despite no clear evidence of malware.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Apr 20, 2026, 05:29 AM
Package URL
pkg:socket/skills-sh/rube-de%2Fcc-skills%2Fjules-review%2F@8dbc93ca339850c9ac404c0412f2432853d49ca6