code-review

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: mostly coherent as a code-review skill, with no direct credential harvesting or exfiltration, but it has two notable risks disproportionate to a pure reviewer: it loads custom guidance from the untrusted PR branch and it encourages installation of another skill, creating a transitive trust chain. Same-org OpenHands references reduce maliciousness concerns, but prompt-influence and trust-extension keep the overall risk at medium.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
May 15, 2026, 02:32 PM
Package URL
pkg:socket/skills-sh/openhands%2Fskills%2Fcode-review%2F@491afa8477868d6bab4f3ddbafe028f2de320fa6
Security Audit — socket — code-review