review-assumptions
Warn
Audited by Socket on May 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose broadly matches its capabilities, but it grants an agent authority to edit and commit code based on report content and depends on unverified internal `codagent:*` skills with unclear provenance. There is no explicit credential harvesting or external exfiltration path in the provided text, so the main concerns are autonomous repository actions, prompt-injection exposure from report ingestion, and unverifiable transitive trust in referenced internal skills.
Confidence: 84%Severity: 58%
Audit Metadata