security-review

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS but not malicious. The skill is internally coherent and uses official tooling, so supply-chain and credential-routing risk are low. However, it materially expands an AI agent into a security scanning/exploit-validation tool, can act on untrusted code and PR comments, can install trust transitively via another skill, and can autonomously write comments/branches/reports. This makes it high-risk operationally even though the stated purpose matches the capabilities.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Apr 23, 2026, 09:57 PM
Package URL
pkg:socket/skills-sh/factory-ai%2Ffactory-plugins%2Fsecurity-review%2F@374dfb46edee4cfc727ef80084038648dd54eb6a