claude-reflect
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s stated purpose and local file access are broadly coherent, and the described data flow is local-only with manual review. The main concern is install trust: evidence points to a third-party plugin marketplace and unverified plugin install path rather than an official Anthropic distribution channel, creating medium supply-chain and transitive-trust risk.
Confidence: 84%Severity: 61%
Audit Metadata