agent-code-review-swarm
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core purpose is coherent for a code-review skill, and GitHub CLI usage/data flow to GitHub are legitimate. The main risk comes from unpinned third-party npm execution (`npx ruv-swarm`), autonomous GitHub write actions, and analyzing untrusted PR content with shell/write-enabled agents; this is high operational risk but not confirmed malware.
Confidence: 83%Severity: 66%
Audit Metadata