claude-code-templates

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's broad install-and-manage purpose largely matches its capabilities, and the primary installer comes from npm with consistent repo linkage. However, mutable `npx @latest`, on-demand remote component fetching, transitive installation of many third-party agent components, and analytics/chat monitoring create medium security risk and unclear data-flow boundaries.

Confidence: 80%Severity: 62%
Audit Metadata
Analyzed At
Mar 21, 2026, 07:19 AM
Package URL
pkg:socket/skills-sh/happycapy-ai%2FHappycapy-skills%2Fclaude-code-templates%2F@07f8d3ff91ead7b475cdce249b75e694971b4ad4