oh-story-claudecode-writing
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core writing and file-management behavior is coherent, and the install path uses a known open-source CLI rather than an opaque binary. However, this skill adds medium risk through transitive skill installation, unpinned supply-chain trust, and browser-CDP scraping that reuses authenticated sessions and processes untrusted external content while the agent can write files.
Confidence: 84%Severity: 57%
Audit Metadata