go-code-review

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core review behavior is broadly aligned with its stated purpose and uses mostly legitimate developer tooling, but its footprint is wider than claimed: it enables Bash execution on untrusted repositories, reads repo-provided instructions, and grants Write/Edit/Skill tools despite asserting strict read-only review. This looks more like an overprivileged review operator than malware, with medium security risk driven by execution and permission scope rather than credential theft or exfiltration.

Confidence: 88%Severity: 61%
Audit Metadata
Analyzed At
Mar 29, 2026, 01:30 PM
Package URL
pkg:socket/skills-sh/notque%2Fclaude-code-toolkit%2Fgo-code-review%2F@3909ff70b00a68f35a322e5b3ab76ac6ef1e8760