security-review

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches security review, but the skill is high risk because it gives an AI agent offensive security-audit capability, processes untrusted diffs while retaining execution/write/posting abilities, executes a repository-local shell script selected by glob, and invokes a second skill transitively. No strong evidence of credential theft or malware, but the capability and execution footprint are dangerous and internally inconsistent with the declared tool restrictions.

Confidence: 91%Severity: 86%
Audit Metadata
Analyzed At
Apr 26, 2026, 10:57 AM
Package URL
pkg:socket/skills-sh/joaquimscosta%2Farkhe-claude-plugins%2Fsecurity-review%2F@5a3910fa563084bb647b4f443ac51d24081e94f8
Security Audit — socket — security-review