performing-security-code-review

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally aligned with its stated purpose, but it grants an AI agent broad security-scanning and arbitrary shell capabilities, including access to sensitive secrets across a codebase. There is no clear evidence of malware or deceptive exfiltration, yet the combination of offensive-security functionality and Bash(cmd:*) makes the overall risk high.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
May 8, 2026, 06:57 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus%2Fperforming-security-code-review%2F@3421372c3e57180f7b41c8189d4c3a8d280f4360
Security Audit — socket — performing-security-code-review