code-reviewer-2
What this skill does
Code review automation for multiple programming languages. Analyzes pull requests for complexity and risk, checks code quality for SOLID violations and code smells, generates review reports.
github/leoyeai - MCP Least Privilege - 2.1k stars
Threat analysis
Skill info
pkg:github/LeoYeAI/openclaw-master-skills@e5199b5?skill=code-reviewer-2Assessments (2)
MCP Least Privilege
MCP Least Privilege via local-llm-review
scripts/pr_analyzer.py
The script uses subprocess.run() to execute external commands, which could potentially be exploited if the command is constructed from untrusted input.MCP Least Privilege via local-llm-review
scripts/review_report_generator.py
The script uses subprocess.run() to execute external commands, which could potentially be exploited if the command is constructed from untrusted input.Badge
Add the Anomity scan badge for code-reviewer-2 to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of code-reviewer-2? Report an issue or request a rescan.




