security-review-3

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the stated purpose is legitimate, but the skill is not self-contained and requires fetching fresh remote instructions from a mutable GitHub URL, then following them. That transitive remote-control pattern is disproportionate for a review skill and materially raises supply-chain and prompt-injection risk, even though the listed audit commands themselves are normal.

Confidence: 87%Severity: 76%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:34 PM
Package URL
pkg:socket/skills-sh/zackkorman%2Fskills%2Fsecurity-review-3%2F@ae27ba1d976c28bca494d0c65247e8dea486d918