review-work

Warn

Audited by Socket on Jul 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core review purpose is plausible, but the skill’s footprint is broad. Parallel autonomous agents, full-code prompt forwarding, and especially external context mining across GitHub/chat/docs create significant data-exposure and prompt-injection risk, while several required agent/tool dependencies are not provenance-verified in the skill text.

Confidence: 86%Severity: 76%
Audit Metadata
Analyzed At
Jul 19, 2026, 05:11 AM
Package URL
pkg:socket/skills-sh/code-yeongyu%2Foh-my-opencode%2Freview-work%2F@34ffb588361f3f3a636b5b38af7c14eec4a56ae1ccdd91aee372a7899c8a47bd
Security Audit — socket — review-work