ccw-chain

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose as an orchestrator is plausible, but its actual footprint is broad and trust-poor. The main concerns are an unverified external chain_loader dependency, wildcard Skill(*) and Bash(*) permissions, transitive execution of other skills, and auto-confirming delegated actions. No direct credential theft or exfiltration is shown, but the orchestration model creates high execution-trust risk.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Apr 6, 2026, 11:09 AM
Package URL
pkg:socket/skills-sh/catlog22%2FClaude-Code-Workflow%2Fccw-chain%2F@b11c85ce66549e8bdde1adfb94ec6212e9874d6c