deep-review

Warn

Audited by Socket on Apr 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is broadly aligned with automated code review, but it has a high-impact autonomous fix-and-stage loop and optional third-party data sharing to external AI CLIs. It does not show clear malware or credential-stealing behavior, yet its write/exec authority over untrusted code and outbound review flows make it a medium-high risk skill.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Apr 5, 2026, 04:00 PM
Package URL
pkg:socket/skills-sh/rhuss%2Fcc-spex%2Fdeep-review%2F@4e37c70132922ee68b8757ee0a39e85e32ab7dcc