ai-review
Warn
Audited by Socket on Aug 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's main behavior is coherent: it sends chosen content to another AI backend for review and clearly warns about third-party disclosure. The main security concern is the sh -c execution of user-controlled AI_REVIEW_CMD, which can run arbitrary commands and redirect reviewed content to unvetted backends; default Codex usage is comparatively lower risk and officially attributable.
Confidence: 89%Severity: 61%
Audit Metadata