ai-code-reviewer

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Functional for its intended goal (multi-model AI code review plus local secret scanning) but exhibits moderate supply-chain and privacy risks. The biggest issues: ambiguous/possibly third-party 'Codex CLI' instruction, lack of explicit user consent and redaction/allowlist controls before sending code externally, and undocumented persistence/encryption of cached analysis. These gaps increase the chance of accidental data exposure when used on sensitive repositories. Recommended mitigations before use on sensitive code: require explicit user consent and per-run confirmation for external sends, provide provenance and verified install URLs/checksums for CLIs, implement file/dir/regex allowlist/denylist and redaction for secrets prior to external transmission, and encrypt and restrict access to the SQLite cache (or avoid persisting raw code).

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 04:20 AM
Package URL
pkg:socket/skills-sh/physics91%2Fclaude-vibe%2Fai-code-reviewer%2F@24692c2ead822446c67d73237e33fe7642c6fa67