security-reviewer

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a security-review skill, but it grants an AI agent offensive security capabilities and shell execution that can be used for penetration testing. There is no clear credential theft, stealth, or exfiltration behavior, so this is high-risk security tooling rather than malware.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 29, 2026, 07:54 PM
Package URL
pkg:socket/skills-sh/Jeffallan%2Fclaude-skills%2Fsecurity-reviewer%2F@4785ccbfb6ee8c2fdc9af3a2746c58b09da5d6a7