adversarial-review
Warn
Audited by Socket on May 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s stated purpose is legitimate code review, but the mandatory use of bypassPermissions for spawned agents is not proportionate to that purpose and weakens user approval safeguards. No malware, exfiltration endpoint, or supply-chain abuse is evident, but the permission-bypass directive makes this a medium/high security-risk skill.
Confidence: 89%Severity: 74%
Audit Metadata