Claude SDK Expert

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill document is a plausible, coherent guide for building Claude Agent SDK-based autonomous agents and aligns capabilities with stated purpose. However, it advocates runtime download-and-execute patterns (npx, docker) without pinning or integrity verification and shows examples that forward environment credentials into spawned third-party processes. Combined with recommended broad computer-use permissions (Bash, filesystem write/edit, all_tools) and examples that let agents execute plans directly, these patterns create a meaningful supply-chain and credential-forwarding risk. The file itself is not demonstrably malicious, but using the described architecture without stricter controls (version pinning, signature verification, least-privilege tooling, stronger command sanitization, explicit approval gates) would leave deployments vulnerable to credential theft, arbitrary code execution, and data exfiltration.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 02:39 AM
Package URL
pkg:socket/skills-sh/frankxai%2Ffrankx.ai-vercel-website%2Fclaude-sdk-expert%2F@2f784c7395fa6b7838de6073bc294be4b58b962f