security-review
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill is purpose-aligned as a security auditing agent and shows no external installer, no credential forwarding, and no remote exfiltration path. However, it grants an autonomous AI agent high-risk offensive security review behavior over the full codebase, reads sensitive files by design, writes local telemetry outside the repo, and references additional slash commands with unverified provenance. High security risk, but not confirmed malware.
Confidence: 91%Severity: 78%
Audit Metadata