recipe-code-review
Warn
Audited by Socket on Jul 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose and capabilities are mostly coherent for a code-review workflow, and there is no clear credential theft or remote exfiltration path. The main issue is install/execution trust: it depends on an under-verified repo-local execution layer (.plan/execute-script.py) and internal extensions with no publicly verified release or signature trail, which makes the skill high risk from a supply-chain perspective rather than malicious by intent.
Confidence: 84%Severity: 72%
Audit Metadata