security-reviewer

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a security-review skill, but it grants an AI agent offensive security capabilities and shell execution that can be used for penetration testing. There is no clear credential theft, stealth, or exfiltration behavior, so this is high-risk security tooling rather than malware.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 29, 2026, 07:54 PM
Package URL
pkg:socket/skills-sh/Jeffallan%2Fclaude-skills%2Fsecurity-reviewer%2F@4785ccbfb6ee8c2fdc9af3a2746c58b09da5d6a7
Security Audit — socket — security-reviewer