claude-code-templates
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's broad install-and-manage purpose largely matches its capabilities, and the primary installer comes from npm with consistent repo linkage. However, mutable `npx @latest`, on-demand remote component fetching, transitive installation of many third-party agent components, and analytics/chat monitoring create medium security risk and unclear data-flow boundaries.
Confidence: 80%Severity: 62%
Audit Metadata