second-opinion

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill's stated purpose — running external LLM-based code reviews on diffs — aligns with the actions it performs (generating diffs, assembling prompts, calling external CLIs). However, several supply-chain and data-exfiltration risks are present and exceed what is strictly necessary for a code-review helper: it sends repository diffs and optional project files to third-party services, recommends installing third-party extensions from GitHub, and explicitly invokes Gemini with --yolo which grants extensions the ability to run actions without confirmation. These behaviors create a high-risk profile for accidental leakage of secrets and for transitive execution of unvetted code. The skill should be treated as suspicious for environments with sensitive data; mitigations should include redacting secrets from diffs, requiring explicit user confirmation before extension actions, avoiding --yolo where possible, validating extension sources, and documenting exactly what data is sent to remote services.

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 10:37 PM
Package URL
pkg:socket/skills-sh/lv416e%2Fdotfiles%2Fsecond-opinion%2F@9820a7b6e2128f664e74cb0896d8807a69965153