code-review

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s core purpose is coherent, and its git/GitHub read operations are proportionate for code review. The main risk is delegation of repository diffs and context to an unverified `popcorn-xp:code-reviewer` agent, combined with classic indirect prompt-injection exposure from untrusted PR content. No clear credential harvesting, malicious exfiltration endpoint, or deceptive install chain is present in the skill text itself, but the unresolved reviewer-agent provenance keeps risk elevated.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 1, 2026, 08:23 PM
Package URL
pkg:socket/skills-sh/mikewolfd%2Fxp-popcorn-skill%2Fcode-review%2F@4d45b49b535519c85a59455272872a7b8bfc0ff9