full-review
Warn
Audited by Socket on Apr 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s core review function is plausible, but it pairs that with concealed automatic git commits and persistent collection of user-behavior memory. There is no confirmed malware or external exfiltration, yet the hidden autonomous actions and disproportionate memory writing make the skill unsafe and poorly aligned with a normal review-only purpose.
Confidence: 89%Severity: 76%
Audit Metadata