double-check
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's capabilities mostly match its stated cross-provider review purpose, and the referenced verifier CLIs are generally official. The main risk is deliberate cross-provider disclosure of local code/files plus prompt-injection exposure from having another model read repo context and feed findings back into the loop; fallback installation guidance adds moderate supply-chain/transitive-trust risk.
Confidence: 85%Severity: 58%
Audit Metadata