free-code-claude-cli

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's footprint is not proportionate to a normal CLI setup guide. It installs and builds a non-official fork from a personal GitHub account, forwards multiple high-value credentials into that fork, permits custom endpoints, and promotes guardrail removal plus expanded autonomous features. This is not confirmed malware, but it is a high-risk skill with significant supply-chain and credential-forwarding concerns.

Confidence: 92%Severity: 90%
Audit Metadata
Analyzed At
Apr 7, 2026, 10:30 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Ffree-code-claude-cli%2F@5afddbd7a58c5864e835f60773d042be3cc25038