review-prompt
Audited by Socket on Aug 26, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: the skill’s core behavior matches its stated prompt-review purpose, but it intentionally exports local code and prompt artifacts to external model services and runs user-specified shell validators. The main concerns are data exposure to /scillm and WebGPT plus partially unverified backend provenance, not confirmed malware.
The code is an LLM-backed prompt-review and gating utility, not clear malware. Its main security concerns are deliberate transmission of potentially sensitive template/source/payload data to configured external services, arbitrary command execution through shell=True for caller-supplied validator and smoke commands, use of an insecure HTTP-capable endpoint and hardcoded development fallback token, and model-controlled rewriting of local files. No evidence of covert exfiltration, persistence, reverse shell, cryptomining, destructive behavior, or credential harvesting is present. The provided fragment is syntactically incomplete and cannot run as written.