claude-code-skill

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill's capabilities mostly match its stated purpose as a multi-engine coding-session orchestrator, and the documented vendor CLIs are broadly consistent with that purpose. Main risks come from third-party orchestration over multiple authenticated AI tools, optional prompt/raw-body logging, and high-autonomy modes like councils and bypassPermissions. This looks more like a high-powered but risky developer automation skill than confirmed malicious behavior.

Confidence: 80%Severity: 61%
Audit Metadata
Analyzed At
May 3, 2026, 02:53 PM
Package URL
pkg:socket/skills-sh/Enderfga%2Fopenclaw-claude-code%2Fclaude-code-skill%2F@1ebc82f2b609466f2bb0e5fe660ec7fe81ff92d5