review-driven-development

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent with its stated issue-to-merge purpose and uses official GitHub/GitLab tooling, so there is no strong malware or installer abuse signal. The main risk is proportionality and data flow: it can autonomously modify/push code and may send full diffs to external AI reviewers, which is plausible for review automation but increases confidentiality and prompt-injection risk.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Mar 18, 2026, 11:27 PM
Package URL
pkg:socket/skills-sh/yvictor%2Fskills%2Freview-driven-development%2F@6f9c53d5011d1f248b8a3acb7eb501929f3c36ed