review-demos

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core review workflow matches the stated purpose, but the skill is over-privileged and high-impact. It reads local secret files, sends some review inputs to a third-party API, and can autonomously write to CRM and Supabase based on untrusted web content. No malware-like payloads or suspicious installers are present, but the data handling and action scope are broader than necessary for QA review.

Confidence: 88%Severity: 66%
Audit Metadata
Analyzed At
Mar 17, 2026, 10:04 AM
Package URL
pkg:socket/skills-sh/psquared-development%2Fpsquared-skills%2Freview-demos%2F@bec60892188e1723016005667632815521fde3df