code-review

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core review behavior fits the stated purpose, but the optional `--multi` path exports code-review content to unspecified external advisor infrastructure, and several invoked tools are custom/undocumented with unverifiable provenance from the skill text alone. This is not fundamentally malicious, but it has medium risk due to external data flow and trust ambiguity around helper commands.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
Apr 3, 2026, 05:36 PM
Package URL
pkg:socket/skills-sh/nielsmadan%2Fagentic-coding%2Fcode-review%2F@4d0728482adff21f9ae1b221e5c152ad5f096627
Security Audit — socket — code-review