vibe-review

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill footprint is coherent with its stated purpose as a code-review helper for C++/Python. It relies on repository data and standard review references without real-world credential access, network exfiltration, or remote execution. The risk profile is low to moderate (benign-to-suspicious depending on how strictly inputs are sanitized); there are no clear indicators of malicious behavior or unnecessary broad access. Overall, the skill appears aligned with its purpose, with minor cautions around ensuring shell command usage remains input-validated to prevent potential command-injection in edge cases.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 11:09 AM
Package URL
pkg:socket/skills-sh/tsukiyokai%2Fvibe-review-skill%2Fvibe-review%2F@071cba289bf9eff41607a94626b2d2cb041f6b0c