auto-review-loop-llm

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's main review-via-LLM behavior is coherent, but it combines broad Bash access, autonomous edit loops, silent execution guidance, and configurable third-party API routing. The biggest risk is confidential project data being sent to arbitrary OpenAI-compatible endpoints under an unattended workflow.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:08 PM
Package URL
pkg:socket/skills-sh/wanshuiyin%2Fauto-claude-code-research-in-sleep%2Fauto-review-loop-llm%2F@f24ff07e1d6a085919b9f7ccc8f82a62966f06709e58c278b48bbbf0e88a83ee
Security Audit — socket — auto-review-loop-llm