claudekit
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose matches workflow scaffolding, but the skill primarily installs a third-party marketplace/plugin and therefore extends trust to external code not reviewed here. No direct credential theft or exfiltration is shown, yet transitive installation plus unpinned third-party source makes this a medium-to-high security risk rather than benign.
Confidence: 84%Severity: 74%
Audit Metadata