ce-review

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core review purpose matches the use of git and GitHub CLI, and install trust is relatively low-risk, but the skill meaningfully expands the agent’s authority through transitive skill calls, parallel sub-agents, and automatic file creation based on untrusted PR content. Main concerns are transitive trust and indirect prompt-injection risk, not confirmed malware or credential theft.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Mar 27, 2026, 05:25 PM
Package URL
pkg:socket/skills-sh/udecode%2Fplate%2Fce-review%2F@9792d0e36bca05bba9263593f09412f6dbf99b5a