security-audit
Warn
Audited by Socket on Mar 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is largely coherent with its stated purpose and uses official GitHub workflows, so it does not look malicious. However, it grants an AI agent high-impact security-review capabilities, can mutate code and GitHub state, and chains into unseen sub-skills, making it medium-risk despite reasonable purpose alignment and approval checkpoints.
Confidence: 84%Severity: 59%
Audit Metadata