review-code

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is purpose-aligned for code review, but its footprint is moderately risky because it turns untrusted review/comment content into direct code edits and executes repo-defined test/lint commands. No obvious credential harvesting, exfiltration endpoint, or malicious install behavior is present.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Mar 16, 2026, 12:28 AM
Package URL
pkg:socket/skills-sh/tobihagemann%2Fturbo%2Freview-code%2F@c9d2855115c7953341d0dc336e2d3b13bdbe2b4b