coderabbit-review
Warn
Audited by Socket on Mar 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s purpose broadly matches its behavior, but install/execution trust is weakened by inconsistent installer guidance. The external CLI provenance is only partially verified, and the documented `pip install coderabbit-cli` fallback does not align with official CodeRabbit docs. Autonomous fix iterations add moderate operational risk, but there is no strong evidence of credential harvesting or clearly malicious data exfiltration beyond expected code review traffic.
Confidence: 84%Severity: 72%
Audit Metadata