respond

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The code fragment constitutes a high-risk, governance-oriented automation blueprint for PR review workflows. It is not malicious, but its radical transparency approach exposes internal reasoning to the public, raising privacy and policy concerns. Recommended improvements include introducing configurable redaction/summarization of reasoning, access-controlled visibility, rate-limiting to prevent PR thread flooding, and explicit safeguards for sensitive content. Treat as SUSPICIOUS from a privacy/governance perspective if no safeguards are implemented, though technically not malware.

Confidence: 65%Severity: 58%
Audit Metadata
Analyzed At
Feb 28, 2026, 04:49 AM
Package URL
pkg:socket/skills-sh/phrazzld%2Fclaude-config%2Frespond%2F@1ae58c065cb76a1530109ed8c506b4460864b261