autonomous-review

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match autonomous PR review, and the cited external tools are official. However, it enables consequential autonomous actions (approve/merge), processes untrusted repo comments/web content while able to execute commands and modify GitHub state, and uses an unpinned MCP install path. No clear credential theft or malicious exfiltration is shown, but the operational risk is high enough to warrant caution.

Confidence: 87%Severity: 76%
Audit Metadata
Analyzed At
Mar 21, 2026, 01:00 AM
Package URL
pkg:socket/skills-sh/zxkane%2Fautonomous-dev-team%2Fautonomous-review%2F@47b0fd13478833ae19633046122d047bad1093a5