agent-code-review
Warn
Audited by Socket on Sep 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s behavior is mostly coherent with its stated PR-review purpose, and the flagged markdown patterns are benign. However, the core `agent-code-review` binary itself is not sourced or verifiable in the skill, while the skill also relies on authenticated GitHub and review-engine CLIs and can autonomously take GitHub actions, including approval. The main concern is install/provenance trust and credentialed external-tool use, not clear malicious intent.
Confidence: 89%Severity: 80%
Audit Metadata