claude-settings-audit

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core repository-audit behavior is mostly coherent and read-only, but the skill overreaches by recommending transitive skills and MCP setups. The Sentry MCP path appears same-org and plausible, yet still introduces a middleware trust boundary; the Linear MCP recommendation is materially inconsistent with Linear's official docs and forwards a sensitive API key to an npx-executed package, making the overall skill medium risk.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Mar 20, 2026, 03:41 AM
Package URL
pkg:socket/skills-sh/getsentry%2Fsentry-skills%2Fclaude-settings-audit%2F@c43289ae827967b34b2084b913a30124eba09819