code-reviewer

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent for a code review skill and there is no clear exfiltration or credential harvesting, but the actual executable component is an unprovided local script with unverifiable provenance and a nonstandard path convention. Risk is mainly from opaque local execution and PR-content handling, not from confirmed malicious behavior.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 18, 2026, 11:22 PM
Package URL
pkg:socket/skills-sh/knowlet%2Fskills%2Fcode-reviewer%2F@aab8b63a82a831ebfc332cef3e9ddf4a135a395d