auto-review-loop

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core purpose matches iterative review, but its actual footprint is much broader than a normal review assistant. Full Bash access, autonomous code/experiment changes, direct external reviewer access to repo contents, optional notifications, and undocumented auxiliary skill/script execution create a high-risk automation and data-leak surface, though there is not enough evidence to call it confirmed malware.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
May 17, 2026, 01:27 AM
Package URL
pkg:socket/skills-sh/wanshuiyin%2FAuto-claude-code-research-in-sleep%2Fauto-review-loop%2F@dcefd6883af7a3b19d077d0d295fe70123f952ce
Security Audit — socket — auto-review-loop