agent-native-reviewer

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose is coherent and its contents are largely benign, but install trust is weakened by conflicting third-party distribution paths and a mutable GitHub zip from an unrelated owner. No evidence of credential harvesting or exfiltration appears in the skill itself, so the main risk is supply-chain and transitive installation rather than malicious behavior.

Confidence: 84%Severity: 55%
Audit Metadata
Analyzed At
Mar 30, 2026, 01:21 AM
Package URL
pkg:socket/skills-sh/udecode%2Fbetter-convex%2Fagent-native-reviewer%2F@88a7edc09243f100d88ed6fe718d213bc840b26f