ralph-kage-bunshin-debug
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core purpose is coherent for a debugger skill, and its main data flow is local plus localhost reporting. The main concern is install trust: the referenced `@anthropic-ai/agent-browser` package appears inconsistent with the provided public evidence, so the optional browser-tool path is not well verified. Also, the skill's 'read-only' claim conflicts with writing to state.json. Overall this is not clearly malicious, but it has medium risk due to the mismatched external install guidance and scope inconsistency.
Confidence: 90%Severity: 58%
Audit Metadata