compose-preview-review

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities are mostly coherent for local Compose UI PR review, but it relies on a transitive bootstrap that pipes a mutable raw GitHub script to bash and installs an external CLI from a personal account. No strong evidence of credential theft or covert exfiltration is present, so this looks like supply-chain/install-trust risk rather than malware.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
May 18, 2026, 07:05 AM
Package URL
pkg:socket/skills-sh/yschimke%2Fskills%2Fcompose-preview-review%2F@24d9638290b9ac56483c2f6b4fab604a875b37a0
Security Audit — socket — compose-preview-review