subagent-review

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent as a deep code-review orchestrator and shows no credential harvesting or external exfiltration, but it materially expands an AI agent's autonomous security-review capability, recursively processes untrusted repository content, and relies on another third-party skill for final plan generation. Main risk is agent misuse and prompt-injection/transitive-trust exposure rather than confirmed malware.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 02:58 PM
Package URL
pkg:socket/skills-sh/DimitriGilbert%2Fai-skills%2Fsubagent-review%2F@19ef5ecd63455c003e73aa8dbede94d81a1c31b1