security-reviewer

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK capability but not malicious: the skill’s footprint is largely consistent with its stated security-audit purpose, uses normal local security tools, and includes authorization guardrails. Its main concern is that it equips an AI agent with offensive security and shell-driven testing capabilities, which are inherently high risk even without clear exfiltration or deceptive behavior.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Sep 4, 2026, 09:19 PM
Package URL
pkg:socket/skills-sh/codeape-7%2Fai-agent-workflowgroup%2Fsecurity-reviewer%2F@5d5dc7ee3bdcd048eb3fc3720b47988c47eff085b61a77b46255e9ae9f5d55d6
Security Audit — socket — security-reviewer