monitor-skill-health
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
AnomalyAnomalyreview.py
LOWAnomalyLOW
review.py
The code is primarily an orchestration wrapper for an external code-review command and contains no clear malware indicators. It does, however, pass audit-controlled paths to the external tool without enforcing workspace containment and forwards nearly the entire environment, which can expose files or credentials if inputs or the invoked reviewer are compromised. Validate result.skill and issue paths with strict containment checks, and pass only an allowlisted environment. The fragment is incomplete at the end, limiting certainty.
Confidence: 96%Severity: 58%
Audit Metadata