review-bugs

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This 'review-bugs' skill is coherent with its stated purpose (read-only code review) and does not contain overtly malicious instructions or hidden network endpoints. The main operational concern is that it requires running git and reading repository files; if executed by an untrusted agent implementation or in an environment without sandboxing, sensitive repository contents could be exposed. Recommend: ensure the agent runs with least privilege, in a sandboxed execution environment, and that logging/export of reports is controlled. No direct malware or credential-harvesting behavior is present in this skill file.

Confidence: 80%Severity: 28%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:30 PM
Package URL
pkg:socket/skills-sh/doodledood%2Fcodex-workflow%2Freview-bugs%2F@70c6524e092c07efac3dce0882deb0822b1730ca