review-assumptions

Warn

Audited by Socket on May 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose broadly matches its capabilities, but it grants an agent authority to edit and commit code based on report content and depends on unverified internal `codagent:*` skills with unclear provenance. There is no explicit credential harvesting or external exfiltration path in the provided text, so the main concerns are autonomous repository actions, prompt-injection exposure from report ingestion, and unverifiable transitive trust in referenced internal skills.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 19, 2026, 04:59 PM
Package URL
pkg:socket/skills-sh/Codagent-AI%2Fagent-skills%2Freview-assumptions%2F@a93445f58adfa29671ad04c1847a2edfb4a36aef
Security Audit — socket — review-assumptions