perform-security-review

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is purpose-aligned and uses official GitHub/local tooling, so it is not malicious or a credential-harvesting lure. However, it meaningfully increases agent capability by enabling offensive-style security analysis, loading additional skills transitively, and feeding untrusted diffs into multiple subagents with Bash/Write access, which makes it a high-impact but coherent security-review skill.

Confidence: 88%Severity: 64%
Audit Metadata
Analyzed At
Apr 10, 2026, 08:12 PM
Package URL
pkg:socket/skills-sh/bitwarden%2Fai-plugins%2Fperform-security-review%2F@41994c40e9605c1f817865ce0d43a4445bc28bdc