critic-review

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core review workflow is coherent, but the skill expands trust boundaries by sourcing raw dotenv files and forwarding those credentials plus plan contents through a local counselors CLI to multiple external model providers. That makes the data flow and credential handling broader than necessary for a review skill, even though the overall purpose is legitimate.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Mar 14, 2026, 12:51 AM
Package URL
pkg:socket/skills-sh/skinnyandbald%2Ffish-skills%2Fcritic-review%2F@14bf8f1fe97f8d74437ee167b23bfbe8ada8acaa