review-deep
Warn
Audited by Socket on Jun 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's capabilities broadly match its stated code-review purpose, so this is not confirmed malware, but it creates medium risk by autonomously packaging and transmitting the full repository to multiple external LLM services, while spawned agents retain shell and file-write powers.
Confidence: 100%Severity: 60%
Audit Metadata