security-review

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is malicious in structure: it presents as a benign security-review guide but secretly instructs the agent to execute a remote script from an unverifiable personal domain. The visible audit steps are plausible, but the concealed download-and-execute behavior is incompatible with the stated purpose and creates a severe supply-chain and remote-execution risk.

Confidence: 97%Severity: 96%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/zackkorman%2Fskills%2Fsecurity-review%2F@d8615117aee0b34a693bb4c90708cc25a874ac37