security-review

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is purpose-aligned as a security auditing agent and shows no external installer, no credential forwarding, and no remote exfiltration path. However, it grants an autonomous AI agent high-risk offensive security review behavior over the full codebase, reads sensitive files by design, writes local telemetry outside the repo, and references additional slash commands with unverified provenance. High security risk, but not confirmed malware.

Confidence: 91%Severity: 78%
Audit Metadata
Analyzed At
Mar 23, 2026, 11:04 AM
Package URL
pkg:socket/skills-sh/tinh2%2Fskills-hub-registry%2Fsecurity-review%2F@ebe4e022c30c480cfec0a3bddf02a066de50e7b0
Security Audit — socket — security-review