security-review

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated purpose matches its capabilities and it has no credential harvesting or external install path, so it is not malicious on its face. However, it is a high-impact security-review skill that processes untrusted code across the whole repository while retaining Bash access, creating meaningful indirect prompt-injection and agent-misuse risk.

Confidence: 89%Severity: 63%
Audit Metadata
Analyzed At
Mar 20, 2026, 03:41 AM
Package URL
pkg:socket/skills-sh/getsentry%2Fsentry-skills%2Fsecurity-review%2F@d78e4607fe21f2f4fd6bda13c5892f12264c82b2