unify
Warn
Audited by Socket on Jun 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core refactoring purpose is coherent, but the skill expands trust by mandating another skill and relying on an external review tool that may receive sensitive repo context or credentials. The main risks are transitive skill installation, third-party tool trust, and prompt-injection exposure during autonomous code analysis/refactoring, not confirmed malware.
Confidence: 100%Severity: 60%
Audit Metadata