review-work
Warn
Audited by Socket on Aug 9, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent, but its footprint is broad. It spawns multiple autonomous sub-agents, copies substantial repo context into child prompts, and encourages mining external collaboration sources, creating medium-high risk from prompt injection, over-collection, and transitive trust in other skills/tools rather than clear malware.
Confidence: 84%Severity: 69%
Audit Metadata