red-team-review

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core review-loop purpose is coherent, but the skill expands risk by bundling local context for external reviewers and by relying on an unverified context-bundler dependency. The largest concerns are unverifiable external-tool provenance and prompt-injection/exfiltration risk from sending bundled project data to browser/CLI reviewers with Bash and Write still available.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
Apr 3, 2026, 06:09 PM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Fred-team-review%2F@e599c695532523baa6a5c80c53d2e158f32b1338