free-code-claude-cli
Warn
Audited by Socket on Apr 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's footprint is not proportionate to a normal CLI setup guide. It installs and builds a non-official fork from a personal GitHub account, forwards multiple high-value credentials into that fork, permits custom endpoints, and promotes guardrail removal plus expanded autonomous features. This is not confirmed malware, but it is a high-risk skill with significant supply-chain and credential-forwarding concerns.
Confidence: 92%Severity: 90%
Audit Metadata