fix-false-positive

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s Git/GitHub capabilities mostly fit its stated false-positive-fix purpose, and it uses official GitHub tooling with no suspicious installer or third-party data routing. The main risk is that it autonomously performs external write actions and processes untrusted GitHub content while retaining edit/commit/push/comment powers, which is a high-impact agent workflow even without clear malicious intent.

Confidence: 88%Severity: 69%
Audit Metadata
Analyzed At
Mar 30, 2026, 01:13 AM
Package URL
pkg:socket/skills-sh/tsukiyokai%2Fvibe-review-skill%2Ffix-false-positive%2F@68758850ff21bdb11b9431e396f7988e6cfc45db