Code & Design Review
Security checks across malware telemetry and agentic risk
Overview
The skill is internally consistent with its stated purpose: it provides local review prompts and simple shell scripts for post‑coding code and UX reviews, and it does not request extra credentials, installs, or network access.
This skill appears coherent and low-risk: the scripts simply format and print code/diffs into review templates and the prompts guide human/AI reviewers. Before installing, consider: (1) Do you want post‑coding reviews to run automatically or only when you invoke them? The README encourages adding mandatory agent instructions — doing so will make reviews run more broadly. (2) The review prompts ask you to paste code or pipe diffs; if your agent sends that data to a remote model (cloud API), sensitive source code may be transmitted off‑site. If your code is sensitive, restrict reviews to local models or run the scripts manually. (3) Inspect and run the two included scripts locally to confirm they behave as expected (they only read files/stdin and print templates). If you accept the integration recommendations, update your agent instruction files deliberately (and back them up) rather than blindly applying them.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
