red-team-review
Warn
Audited by Socket on Apr 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core review-loop purpose is coherent, but the skill expands risk by bundling local context for external reviewers and by relying on an unverified context-bundler dependency. The largest concerns are unverifiable external-tool provenance and prompt-injection/exfiltration risk from sending bundled project data to browser/CLI reviewers with Bash and Write still available.
Confidence: 82%Severity: 74%
Audit Metadata