security-review

Fail

Audited by Socket on Mar 2, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The fragment presents a questionable security-review workflow that intertwines defensive scanning with offensive exploit-generation, creating meaningful risk of misuse and collateral impact. While structured like a comprehensive security process, the mandatory exploitation phase and PoC templates are misaligned with safe, governance-driven security auditing practices. A removal or strict gating of exploit generation, along with enhanced safety controls, sandboxing, and authorization, is required to make this usable in a real-world open-source supply-chain context.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 2, 2026, 04:16 PM
Package URL
pkg:socket/skills-sh/Dilaz%2Fsecurity-review-skill%2Fsecurity-review%2F@d154bc31f36e81561a5712a53edd9e99114bb113