code-quality-specialist

Warn

Audited by Socket on Mar 16, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/domains/skill-quality/tuning/phases/actions/action-init.md

This code implements a benign orchestration initializer but contains an unsafe pattern: direct interpolation of user/caller-supplied paths into Bash()-invoked shell commands. That leads to a realistic risk of command injection, path traversal, and unintended filesystem access. There is no evidence of explicit malware (no network exfiltration, no obfuscated payloads, no hardcoded credentials), but the unsafe shell use makes this module a security hazard if inputs are untrusted or controlled by an attacker.

Confidence: 90%Severity: 60%
AnomalyLOW
references/domains/skill-quality/tuning/phases/actions/action-gemini-analysis.md

No explicit malicious code is present in this module itself — it is an orchestration wrapper that constructs prompts and runs an external CLI. The primary security concern is unsafe shell command construction using user-controlled inputs (insufficient escaping) and delegation to an external CLI run in background, which can lead to command injection or unintended data exfiltration if inputs are malicious or if the CLI is compromised. Treat this package as functionally benign but moderately risky without remediation of the command construction and input handling.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Mar 16, 2026, 04:40 AM
Package URL
pkg:socket/skills-sh/prorise-cool%2Fprorise-claude-skills%2Fcode-quality-specialist%2F@d58368f6b4051dd14bb6b4740513bfcab8bb1bcd