security-reviewer

Warn

Audited by Socket on Aug 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is coherent with its stated purpose, but that purpose is itself high risk: it equips an AI agent to run security scans and potentially active penetration-testing actions with Bash access. Install trust is mostly acceptable because the named tools are official third-party security utilities, but scope and autonomy risk remain high because the skill cannot technically enforce authorization or prevent misuse against unintended targets.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Aug 2, 2026, 03:59 PM
Package URL
pkg:socket/skills-sh/hosseinmirzapur%2Fopencode-skills%2Fsecurity-reviewer%2F@0f17b45f696021192574916a4b34064462a40f87a575980d61214daf05370356
Security Audit — socket — security-reviewer