workflow-review-changes

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent for code-review automation, and it shows no external installer or credential-harvesting path. Risk comes from broad autonomous orchestration, recursive delegation to many other unverified slash-workflows, and prompt-injection exposure from reviewing attacker-controlled repo content before taking write actions.

Confidence: 82%Severity: 59%
Audit Metadata
Analyzed At
May 1, 2026, 05:53 PM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fworkflow-review-changes%2F@9431cacde6bd0b63784d7a9ff1608938088dd28a