clinical-trial-protocol-skill

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill's functionality and described capabilities are coherent with its stated purpose. There are no code snippets or artifacts in this fragment that indicate direct malicious payloads, obfuscation, or backdoors. However, the required external MCP server (Claude Desktop plugin) is a notable network dependency and a potential data-exfiltration conduit for sensitive user-supplied documents stored in waypoints. The skill stores user-provided materials in plaintext waypoint files and performs automatic MCP connectivity checks, which raises privacy and supply-chain trust concerns. Recommend treating the MCP dependency as a trusted component only after verification, avoid uploading PHI or sensitive proprietary data without review, and inspect all references/*.md subskills before execution to ensure no hidden instructions. Overall: low probability of malware, but moderate security/privacy risk due to external dependency and storage of sensitive inputs.

Confidence: 75%Severity: 55%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:33 PM
Package URL
pkg:socket/skills-sh/anthropics%2Fhealthcare%2Fclinical-trial-protocol-skill%2F@95419dfb4f54209d6613b09bde0a99e9cade8289