classify-review

Warn

Audited by Socket on Aug 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Mostly coherent with its stated PR-comment false-positive filtering purpose. Main risk is the required but unreviewed local updater script plus moderate prompt-injection exposure from sending untrusted review comments to a subagent that can trigger a Bash-driven state update; data flow otherwise appears proportionate and directed to official Anthropic services.

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
Aug 11, 2026, 05:08 PM
Package URL
pkg:socket/skills-sh/cor-incorporated%2Fclaude-code-skills%2Fclassify-review%2F@647bee9b7a8847c20f104b3477c1973f0a3cb9e581fe203fc933dd35e0da5262
Security Audit — socket — classify-review