vp-review
Warn
Audited by Socket on Apr 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core review purpose is coherent and there is no clear credential theft or exfiltration path, but the skill expands its footprint by telling the agent to load unspecified other skills and consume untrusted external content with tool/subagent access. The main concern is transitive trust and prompt-injection exposure, not confirmed malware.
Confidence: 84%Severity: 58%
Audit Metadata