agent-code-review

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s behavior is mostly coherent with its stated PR-review purpose, and the flagged markdown patterns are benign. However, the core `agent-code-review` binary itself is not sourced or verifiable in the skill, while the skill also relies on authenticated GitHub and review-engine CLIs and can autonomously take GitHub actions, including approval. The main concern is install/provenance trust and credentialed external-tool use, not clear malicious intent.

Confidence: 89%Severity: 80%
Audit Metadata
Analyzed At
Sep 11, 2026, 11:52 PM
Package URL
pkg:socket/skills-sh/shhac%2Fagent-skills%2Fagent-code-review%2F@9fe56099fb4a2fd816f66f337f7bf55d2fbd2e1f61499a551140e232eb9f7ef7
Security Audit — socket — agent-code-review