openclaude-multi-llm

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose matches its core behavior, but it asks users to trust a third-party Claude Code fork that intercepts all model traffic, forwards credentials and tool context to arbitrary OpenAI-compatible endpoints, and may read Codex auth files. The main issue is high trust plus broad data exposure, not confirmed malware.

Confidence: 86%Severity: 79%
Audit Metadata
Analyzed At
Apr 1, 2026, 12:31 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fopenclaude-multi-llm%2F@68a1e1be5eea8f2997f1f0d5bdb24d33f78bff56