agent-code-review-swarm

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose is coherent for a code-review skill, and GitHub CLI usage/data flow to GitHub are legitimate. The main risk comes from unpinned third-party npm execution (`npx ruv-swarm`), autonomous GitHub write actions, and analyzing untrusted PR content with shell/write-enabled agents; this is high operational risk but not confirmed malware.

Confidence: 83%Severity: 66%
Audit Metadata
Analyzed At
Sep 15, 2026, 11:37 AM
Package URL
pkg:socket/skills-sh/ruvnet%2Fruflo%2Fagent-code-review-swarm%2F@849650f1adf1d37b0ac3cbc001c26fd9c1fa6deebad25ff57321c52be1057d2a
Security Audit — socket — agent-code-review-swarm