review-security

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally aligned with its purpose and has no clear credential theft or exfiltration path, so it is not malicious. Risk is elevated because it grants an AI agent offensive security-review capability and processes untrusted repository content with limited bash access, creating indirect prompt-injection and misuse concerns; install trust for the skill content itself is otherwise low-to-moderate.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Mar 26, 2026, 08:44 PM
Package URL
pkg:socket/skills-sh/mgiovani%2Fcc-arsenal%2Freview-security%2F@85e7d98882bfb50b1f4f599f3bdb81acfe72342a