subagent-review
Warn
Audited by Socket on May 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is coherent as a deep code-review orchestrator and shows no credential harvesting or external exfiltration, but it materially expands an AI agent's autonomous security-review capability, recursively processes untrusted repository content, and relies on another third-party skill for final plan generation. Main risk is agent misuse and prompt-injection/transitive-trust exposure rather than confirmed malware.
Confidence: 100%Severity: 60%
Audit Metadata