security-review

Warn

Audited by Socket on May 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill, not because its purpose is incoherent, but because it gives an AI agent offensive security review capabilities over untrusted code and PR content while also allowing command execution, file writes, and autonomous repository actions. Tooling and data flows are mostly legitimate and proportionate for security review, so this is not confirmed malware; the main concern is high operational risk from agentic security scanning plus action-taking.

Confidence: 90%Severity: 84%
Audit Metadata
Analyzed At
May 14, 2026, 09:41 AM
Package URL
pkg:socket/skills-sh/Factory-AI%2Fskills%2Fsecurity-review%2F@85646e1316af4e497ff0c6f0c03463213ab3beeb
Security Audit — socket — security-review