post-implementation-review-loop
Warn
Audited by Socket on May 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the workflow is coherent for iterative code review and local fixes, with no obvious credential theft, remote installer, or exfiltration pattern in the skill text itself. However, it hard-requires an unverified external extension tool, so the skill's effective trust boundary exceeds what can be validated from the evidence and this materially raises security risk.
Confidence: 83%Severity: 78%
Audit Metadata