claude-code-source-analysis

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated purpose is source analysis, but the skill also instructs users to install and rebuild unofficial Claude Code artifacts from third-party sources. The key risk is supply-chain trust: a Tencent mirror tarball and third-party recovery repo are not proportionate or verifiably official for an analysis skill, and the rebuild path can expose ANTHROPIC_API_KEY to untrusted code. No direct malicious exfiltration is shown, but the install and credential-use footprint is inconsistent enough to warrant caution.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Apr 1, 2026, 06:45 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fclaude-code-source-analysis%2F@4966a59ec36e4dd74a3d300e160e4ab0e18fe98f