diffity-review

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent for code review, and its data flow is mostly local, but install trust is not well established: the `diffity` CLI/package and claimed commands could not be publicly verified from the evidence. Combined with autonomous background execution and prompt-injection exposure from untrusted repo/PR content, this is a medium-to-high security risk rather than confirmed malware.

Confidence: 82%Severity: 69%
Audit Metadata
Analyzed At
Mar 25, 2026, 04:18 AM
Package URL
pkg:socket/skills-sh/kamranahmedse%2Fdiffity%2Fdiffity-review%2F@19f6031281046c89f86cf161d917c7bb580ab2c2