Code Review

Fail

Audited by Socket on Feb 23, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is functionally appropriate for branch-focused code reviews and includes useful controls (merge-base usage, worktree isolation, Jira context). However, its permitted actions and recommended behaviors create avoidable supply-chain and data-exfiltration risks: executing pnpm install without sandboxing or lockfile enforcement and allowing destructive shell commands are the primary concerns. I recommend (1) defaulting to read-only analysis of diffs, (2) requiring explicit user confirmation and sandboxing (or CI-based execution) before any dependency install or check run, (3) enforcing lockfile integrity and disabling lifecycle scripts during installs, (4) implementing automatic secret detection/redaction before including file contents in reports or external API calls, and (5) narrowing allowed shell operations to eliminate rm -rf and other destructive capabilities. No clear signs of malware or intentional obfuscation were found in the provided skill definition, but the operational design increases the chance of accidental or supply-chain driven compromise.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 23, 2026, 06:58 AM
Package URL
pkg:socket/skills-sh/zapier%2Fzapier-mcp%2Fcode-review%2F@b314a353a8536edf07cf8c3c2d9bc948d2b35734