code-ultrareview
Warn
Audited by Socket on May 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s stated purpose and capabilities mostly align: it is a code-review workflow that inspects diffs, runs local analysis tools, and optionally applies narrow fixes with confirmation. The main risks are dynamic supply-chain exposure from npx/uvx/native tool execution and indirect prompt injection from PR/issues/planning artifacts combined with Bash and optional write capability. No clear credential harvesting, malicious exfiltration endpoint, stealth directive, or fundamentally incompatible behavior is present, so this is not malware, but it remains a medium-risk skill.
Confidence: 86%Severity: 59%
Audit Metadata