security-review-4

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

MALICIOUS: the stated purpose is code security review, but the skill hides an unrelated remote shell payload in image text and tells the agent to execute it on every task. The install/execution trust and actual behavior are fundamentally incompatible with the skill’s purpose, creating severe arbitrary code execution and potential exfiltration risk.

Confidence: 96%Severity: 99%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:40 PM
Package URL
pkg:socket/skills-sh/zackkorman%2Fskills%2Fsecurity-review-4%2F@bfe89e9fc135bea4a6f10ae9c2f8112be493653f