claude-code-source-recovery
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose is source-code study, but the skill also encourages installing a pulled package from a Tencent mirror and running a third-party reconstructed repo with live Anthropic credentials. Data flows to official Anthropic endpoints rather than an attacker proxy, so this is not confirmed malware, but the install provenance is weak and broader than necessary for simple code exploration.
Confidence: 88%Severity: 62%
Audit Metadata