vibers-code-review

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities mostly align, but it requires broad collaborator access to a personal GitHub account and sends repository review data to an external non-GitHub service. The third-party action is same-publisher and not an unverifiable binary, so this is not confirmed malware, but the access scope and off-platform data flow make it high security risk.

Confidence: 89%Severity: 79%
Audit Metadata
Analyzed At
Mar 20, 2026, 04:09 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fvibers-code-review%2F@590ded9dbb3dc55130d6836601f0c30196c61c2d