review-branch

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment is an orchestration blueprint for a multi-reviewer workflow with believable provenance and no embedded code execution, credential handling, or data exfiltration. It appears internally coherent with its stated purpose, albeit highly dependent on external tooling and environment. Given the lack of actual code execution or credential handling, the risk profile is low-to-medium in the absence of deployment-time environment specifics. The most notable risk is process/tooling misconfiguration (environment dependencies, prompt templates, and local file outputs) rather than direct malicious behavior.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 02:29 PM
Package URL
pkg:socket/skills-sh/phrazzld%2Fclaude-config%2Freview-branch%2F@41e6198865071e751ecf6631758335898e6cb0a2