claude-skill
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS: the skill's core purpose is coherent, and the main Claude Code install source is legitimate, but its footprint is high-risk because it removes approval barriers and enables autonomous code changes, pushes, PR operations, and review actions. The main concern is not hidden malware behavior; it is disproportionate autonomy plus external-content-to-execution risk across multiple CLIs.
Confidence: 90%Severity: 78%
Audit Metadata