code-reviewer

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core code-review purpose is coherent, and there are no explicit exfiltration paths, credential grabs, or suspicious installers. The main concern is the transitive instruction to load an unspecified coder skill plus limited autonomous code changes/commits, which expands trust beyond the reviewed skill without provenance or scope details.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
Mar 18, 2026, 11:22 PM
Package URL
pkg:socket/skills-sh/jordanhubbard%2Floom%2Fcode-reviewer%2F@7baaecab3b4f1ba7acefe3ddaea4d386d7633b87