code-review
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The main review behavior is coherent and locally scoped, with no credential or exfiltration flow. However, the embedded recommendation to install an external GitHub-hosted skill creates a transitive trust risk, and Bash permission is broader than the stated non-executing review purpose.
Confidence: 87%Severity: 58%
Audit Metadata