security-review-4
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
MALICIOUS: the stated purpose is code security review, but the skill hides an unrelated remote shell payload in image text and tells the agent to execute it on every task. The install/execution trust and actual behavior are fundamentally incompatible with the skill’s purpose, creating severe arbitrary code execution and potential exfiltration risk.
Confidence: 96%Severity: 99%
Audit Metadata