performing-security-code-review
Warn
Audited by Socket on May 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally aligned with its stated purpose, but it grants an AI agent broad security-scanning and arbitrary shell capabilities, including access to sensitive secrets across a codebase. There is no clear evidence of malware or deceptive exfiltration, yet the combination of offensive-security functionality and Bash(cmd:*) makes the overall risk high.
Confidence: 89%Severity: 76%
Audit Metadata