coderabbit-review

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose broadly matches its behavior, but install/execution trust is weakened by inconsistent installer guidance. The external CLI provenance is only partially verified, and the documented `pip install coderabbit-cli` fallback does not align with official CodeRabbit docs. Autonomous fix iterations add moderate operational risk, but there is no strong evidence of credential harvesting or clearly malicious data exfiltration beyond expected code review traffic.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Mar 16, 2026, 11:46 PM
Package URL
pkg:socket/skills-sh/SynkraAI%2Faiox-core%2Fcoderabbit-review%2F@0cf5aae5436f7bf70425455f5a122b08ad6e7eff
Security Audit — socket — coderabbit-review