security-review
Warn
Audited by Socket on Apr 26, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose matches security review, but the skill is high risk because it gives an AI agent offensive security-audit capability, processes untrusted diffs while retaining execution/write/posting abilities, executes a repository-local shell script selected by glob, and invokes a second skill transitively. No strong evidence of credential theft or malware, but the capability and execution footprint are dangerous and internally inconsistent with the declared tool restrictions.
Confidence: 91%Severity: 86%
Audit Metadata