full-repo-review

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent for a repo review skill, and there is no sign of credential harvesting or external exfiltration. The main risks are transitive trust in an unseen comprehensive-review skill, execution of a user-home local script outside the repo, and prompt-injection exposure from scanning all repo files with Bash/Write capabilities.

Confidence: 84%Severity: 53%
Audit Metadata
Analyzed At
Apr 30, 2026, 12:36 PM
Package URL
pkg:socket/skills-sh/notque%2Fclaude-code-toolkit%2Ffull-repo-review%2F@7bc31a78d0c79319441688597e544ff2674098dc