ce-review

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core review purpose matches the use of git and GitHub CLI, and install trust is relatively low-risk, but the skill meaningfully expands the agent’s authority through transitive skill calls, parallel sub-agents, and automatic file creation based on untrusted PR content. Main concerns are transitive trust and indirect prompt-injection risk, not confirmed malware or credential theft.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Mar 15, 2026, 06:11 AM
Package URL
pkg:socket/skills-sh/udecode%2Fplate%2Fce-review%2F@1e7ec9f3b98678845c38e9a87826a66d273425c6