OverviewHistoryStatsSecurity
Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Warn4 providerslatest audit Apr 2, 2026
Independent checks from skills.sh's audit partners.
The skill is generally well-structured for code analysis but contains potential command and argument injection vulnerabilities in its Git integration scripts. Specifically, user-provided branch names and repository paths are passed as arguments to subprocess calls without sufficient sanitization, which could allow a malicious actor to execute unintended Git commands or manipulate the review process. Additionally, the skill's reliance on processing external code creates a surface for indirect prompt injection.
Detected behaviors
No alerts
No issues
2/7 files flagged