performing-security-code-review

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS rather than malicious. The skill’s core behavior matches its stated purpose, and the visible data flows are mostly local and proportionate, but it grants an AI agent broad shell access and explicit security-scanning capability, which materially raises risk. No clear credential harvesting or covert exfiltration is shown in the provided skill text.

Confidence: 87%Severity: 71%
Audit Metadata
Analyzed At
Apr 8, 2026, 09:47 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fperforming-security-code-review%2F@759fc3ffb6ebf2c45cd96d6ff36878ffee8d944c