production-code-audit

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's high-level purpose (automated production-grade audit and remediation) is plausible, but its default autonomy (read every file, modify codebase, run tests, create integrations) is dangerous. There is no explicit malicious payload in the provided spec, but the behavior enables multiple supply-chain and data-exfiltration risks if executed without strict controls. Treat the skill as unsafe to run in autonomous write/execute mode. Recommended: restrict to read-only analysis, require explicit per-change approval, sandbox any execution of repository code, never auto-install or send discovered secrets, and require user-provided, vetted endpoints/credentials for integrations.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fproduction-code-audit%2F@2b865b872fe684f301ce1f97eb801fef3ccdbe19