security-review

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent and not malware-like: no downloads, no external endpoints, no credential forwarding, and no hidden data exfiltration paths. But it equips an AI agent with offensive security review capabilities plus Bash execution, which is a high-risk class of skill even when framed as auditing, so the overall risk is elevated despite low supply-chain and credential risk.

Confidence: 91%Severity: 72%
Audit Metadata
Analyzed At
Mar 21, 2026, 09:43 AM
Package URL
pkg:socket/skills-sh/derklinke%2Fcodex-config%2Fsecurity-review%2F@9a2a38d1e34b296a9aaaef1bb5221c6a294a93b7
Security Audit — socket — security-review