review-package

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The overall workflow matches the claimed purpose of creating a review bundle, and no direct network exfiltration or credential harvesting is visible. However, the skill relies on an unverifiable local shell script and an unseen local subagent from ~/.claude, so execution trust is weaker than the documentation implies; this raises security risk even though malicious intent is not confirmed.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:40 PM
Package URL
pkg:socket/skills-sh/petekp%2Fclaude-code-setup%2Freview-package%2F@a032339b5d3495fb8d5aa3375fc3597be7a4f307