review-security

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated purpose as a read-only security review workflow, and its tool references are proportionate and largely official. The main concern is that it operationalizes AI-driven security scanning over untrusted repository/PR content with shell access, creating meaningful indirect prompt-injection and offensive-use risk even without explicit exfiltration or malicious install behavior.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
May 9, 2026, 04:33 PM
Package URL
pkg:socket/skills-sh/mgiovani%2Fskills%2Freview-security%2F@a10e02c5d2b9edc72cd468035bdb5c5ec46295af
Security Audit — socket — review-security