review-implement
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is broadly aligned with a review-to-implementation workflow, but it grants high autonomy for code changes, PR creation, and bot interaction without user approval checkpoints, and it transitively relies on other unspecified skills. No direct malware, credential theft, or external exfiltration is visible in this file, so the main risk is over-broad autonomous action and unreviewed trust chaining rather than confirmed malicious behavior.
Confidence: 87%Severity: 72%
Audit Metadata