autoreview

Warn

Audited by Socket on May 29, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/test-review-harness

This is a local security-review harness that deliberately generates a high-risk malicious fixture containing a destructive execSync(rm -rf ...) sink with untrusted interpolation and a sensitive-data exposure pattern (returning password). The harness itself mainly performs repo setup and invokes an external review tool; it does not execute the fixture. Overall risk is driven by accidental execution or reuse of the malicious fixture code rather than covert malware or network-based compromise in the harness itself.

Confidence: 70%Severity: 62%
Audit Metadata
Analyzed At
May 29, 2026, 05:04 PM
Package URL
pkg:socket/skills-sh/uinaf%2Fagents%2Fautoreview%2F@4147b0ebc887c1ed23191b76b6b586075b94f9f4
Security Audit — socket — autoreview