adversarial-review

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but it routes local code/diffs and guidance files through an external opposite-model CLI, creating meaningful confidentiality and prompt-injection risk. Install trust for `codex exec` appears acceptable from the provided evidence, so this is not confirmed malicious; the main issue is proportional data exposure and reduced transparency from shell-based background execution.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Apr 15, 2026, 12:15 AM
Package URL
pkg:socket/skills-sh/pedronauck%2Fkodebase-go%2Fadversarial-review%2F@3afe99a793d18e712f5a354e7868e0ea34ba2e05