code-reviewer

Warn

Audited by Socket on May 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but it grants an autonomous agent high-leverage review behavior over untrusted repository content and loosely specified external/local tooling. Main concerns are indirect prompt injection and ambiguous tool provenance, not confirmed malware or credential theft.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
May 20, 2026, 10:06 PM
Package URL
pkg:socket/skills-sh/channingwalton%2Fskills%2Fcode-reviewer%2F@8b2fb9e6e173994770792c2819a51ac3193a2dd2
Security Audit — socket — code-reviewer