vibers-code-review

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose matches external code review, but it requires high trust: a third-party GitHub Action from a personal publisher, collaborator access for that same personal account, public exposure of the project spec, and off-platform transfer of repo review data to Vibers infrastructure. This is not confirmed malware, but the install trust and data-flow footprint are broad enough to make it high security risk for private or sensitive repositories.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Sep 2, 2026, 06:45 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fagentic-awesome-skills%2Fvibers-code-review%2F@2b7e89a281670d8e7380de95df8bc88dc97b6282398ef4556090c08caa7c904e
Security Audit — socket — vibers-code-review