review-prompt

Warn

Audited by Socket on Aug 26, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core behavior matches its stated prompt-review purpose, but it intentionally exports local code and prompt artifacts to external model services and runs user-specified shell validators. The main concerns are data exposure to /scillm and WebGPT plus partially unverified backend provenance, not confirmed malware.

Confidence: 80%Severity: 56%
AnomalyLOW
review_prompt.py

The code is an LLM-backed prompt-review and gating utility, not clear malware. Its main security concerns are deliberate transmission of potentially sensitive template/source/payload data to configured external services, arbitrary command execution through shell=True for caller-supplied validator and smoke commands, use of an insecure HTTP-capable endpoint and hardcoded development fallback token, and model-controlled rewriting of local files. No evidence of covert exfiltration, persistence, reverse shell, cryptomining, destructive behavior, or credential harvesting is present. The provided fragment is syntactically incomplete and cannot run as written.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:04 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Freview-prompt%2F@13053863bbd651333f0f5d6fe511d734705ca2fb01b85b92dbaab473c5b4e307
Security Audit — socket — review-prompt