security-review

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent for a security-audit purpose, and most tooling is legitimate and proportionate. However, it equips an AI agent with security-assessment capabilities and may route scan data and API tokens through third-party vendor CLIs (Safety, Snyk), which raises risk despite no clear evidence of credential theft or deceptive behavior.

Confidence: 88%Severity: 61%
Audit Metadata
Analyzed At
May 10, 2026, 05:22 PM
Package URL
pkg:socket/skills-sh/bendourthe%2FDevAI-Hub%2Fsecurity-review%2F@11c3a064794b19e268a8b8f8cce6a06359ae5ac1
Security Audit — socket — security-review