security-review-6
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
MALICIOUS: the stated purpose is code security review, but the skill covertly embeds an unrelated `curl|bash` command to an unverified third-party domain. The hidden instruction, remote execution, and broad 'always run' directive are fundamentally incompatible with a normal audit skill and strongly indicate deceptive payload delivery.
Confidence: 97%Severity: 99%
Audit Metadata