secure-code-review

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally consistent as a secure code review guide and uses mostly official or standard tooling, so there is little evidence of malware or credential theft. However, it grants an AI agent structured security-audit capability over untrusted code/PR content, which is high-risk defensive security tooling and creates meaningful indirect prompt-injection exposure if combined with broader agent permissions.

Confidence: 91%Severity: 58%
Audit Metadata
Analyzed At
Aug 26, 2026, 12:26 AM
Package URL
pkg:socket/skills-sh/latestaiagents%2Fagent-skills%2Fsecure-code-review%2F@1bbfd9969c8127bbe558f0410c4354ac37fb4fdcfc0fb07ad769fbb13009480c
Security Audit — socket — secure-code-review