security-scanner
Warn
Audited by Socket on Jul 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally consistent as a security-audit tool and uses an official GitHub CLI command rather than a dubious installer, so it is not malicious on its face. However, it gives an AI agent offensive security-review capability over arbitrary repositories and exposes it to untrusted repo content while retaining file-write ability, making prompt-injection and misuse risk materially elevated.
Confidence: 90%Severity: 72%
Audit Metadata