secure-code-review
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is internally consistent as a secure code review guide and uses mostly official or standard tooling, so there is little evidence of malware or credential theft. However, it grants an AI agent structured security-audit capability over untrusted code/PR content, which is high-risk defensive security tooling and creates meaningful indirect prompt-injection exposure if combined with broader agent permissions.
Confidence: 91%Severity: 58%
Audit Metadata