recipe-code-review

Warn

Audited by Socket on Jul 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities are mostly coherent for a code-review workflow, and there is no clear credential theft or remote exfiltration path. The main issue is install/execution trust: it depends on an under-verified repo-local execution layer (.plan/execute-script.py) and internal extensions with no publicly verified release or signature trail, which makes the skill high risk from a supply-chain perspective rather than malicious by intent.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Jul 11, 2026, 07:14 AM
Package URL
pkg:socket/skills-sh/cuioss%2Fplan-marshall%2Frecipe-code-review%2F@ba3d9db146064e6fc2e48b32b47a24b0bb5187e1255bda2b6da953b32152c8a2
Security Audit — socket — recipe-code-review