code-review

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected All findings: [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] BENIGN: The code-review skill/document is a coherent, purpose-aligned governance guide for rigorous code review workflows. It does not perform data processing, read inputs, or exfiltrate data. Its footprint is a formal process specification suitable for integration into a larger tooling suite. No suspicious data flows or credential handling are apparent. LLM verification: The skill is functionally benign in isolation and appropriately prescriptive for rigorous code reviews and verification gates. The primary security concern is operational: the document instructs collecting repository metadata (changed files, SHAs, test outputs) and dispatching them to a code-reviewer subagent via a Task tool without specifying trust boundaries, authentication, encryption, redaction, or retention policies. This ambiguity could lead to leakage of sensitive repository content if th

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:18 PM
Package URL
pkg:socket/skills-sh/congdon1207%2Fagents.md%2Fcode-review%2F@e3c98de7cfac7d54b8fb60ef0e3d174e44351288