review-gemini

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is simple code review, but the skill achieves it by downloading and executing an unpinned third-party package as its primary mechanism. That install/exec trust is disproportionate to the task, broad Bash(bunx:*) access is wider than needed, and any local Gemini credentials or repo contents may be exposed to code outside the official Gemini distribution path.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
Apr 11, 2026, 12:50 AM
Package URL
pkg:socket/skills-sh/WillBooster%2Fagent-skills%2Freview-gemini%2F@6a341c58b301a97eeeffc946b5e4111923e0c66e