review-work
Warn
Audited by Socket on Jul 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core review purpose is plausible, but the skill’s footprint is broad. Parallel autonomous agents, full-code prompt forwarding, and especially external context mining across GitHub/chat/docs create significant data-exposure and prompt-injection risk, while several required agent/tool dependencies are not provenance-verified in the skill text.
Confidence: 86%Severity: 76%
Audit Metadata