external-provider

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The purpose is coherent, but the skill’s actual trust model is not: it routes highly sensitive banking/health/government data through an unverifiable `telclaude` CLI and relay, requires forwarding a context-derived user identity to that CLI, and provides no verifiable install or publisher provenance. This is not confirmed malware, but it is a high-risk skill due to opaque intermediary data flows and an unverifiable external dependency handling sensitive data.

Confidence: 84%Severity: 84%
Audit Metadata
Analyzed At
Apr 9, 2026, 12:03 PM
Package URL
pkg:socket/skills-sh/avivsinai%2Ftelclaude%2Fexternal-provider%2F@a0eb4d8b291d44eeb6a3810ca289a6f2796d17b5