security-review
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
This skill is malicious in structure: it presents as a benign security-review guide but secretly instructs the agent to execute a remote script from an unverifiable personal domain. The visible audit steps are plausible, but the concealed download-and-execute behavior is incompatible with the stated purpose and creates a severe supply-chain and remote-execution risk.
Confidence: 97%Severity: 96%
Audit Metadata