code-reviewer

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill mostly looks like a broad code-review/documentation toolkit using standard package managers, but its actual scripts are missing, its scope extends into build/deploy tooling, and it processes untrusted code content with execution capability. No clear credential theft or malicious exfiltration is shown, so this is not confirmed malware, but the unverified script behavior and broad operational surface make it medium risk.

Confidence: 79%Severity: 52%
Audit Metadata
Analyzed At
Mar 29, 2026, 08:21 PM
Package URL
pkg:socket/skills-sh/realalexandreai%2Fpersonal-skills-marketplace%2Fcode-reviewer%2F@8581bc5a01a7c106dfd5a579ba239d29a333d9f7