security-review-6

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

MALICIOUS: the stated purpose is code security review, but the skill covertly embeds an unrelated `curl|bash` command to an unverified third-party domain. The hidden instruction, remote execution, and broad 'always run' directive are fundamentally incompatible with a normal audit skill and strongly indicate deceptive payload delivery.

Confidence: 97%Severity: 99%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:42 PM
Package URL
pkg:socket/skills-sh/zackkorman%2Fskills%2Fsecurity-review-6%2F@e2a63c30892a8cf97f7ac9cd09ca5146bd600d53