skill-reviewer

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Benign. The provided skill-reviewer content is a documentation-heavy auditing framework intended to evaluate other skills. It does not appear to perform runtime actions, exfiltrate data, or install/unverified binaries. Its primary footprint is static guidance, structure validation, and scoring rubrics. While there are potential improvements to tighten security practices (e.g., explicit avoidance of unverified sources in any recommended workflows), there is no evidence of malicious or high-risk behavior in the described artifacts. Overall, the footprint is coherent with its stated purpose as a governance/audit tool rather than a capability that manipulates or exfiltrates user data.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 08:27 AM
Package URL
pkg:socket/skills-sh/xzxiaoshan%2Fagent-skills%2Fskill-reviewer%2F@e4c98be2e5b6b5b10f42017e4860ffbb9fb1eeb2