clay-migration-deep-dive

Fail

Audited by Socket on Feb 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] The skill fragment is coherent with its stated purpose of guiding and implementing a Clay migration using a Strangler Fig pattern. It presents plausible prerequisites, phased implementation, rollback, and validation steps. No clear malicious activity or credential harvesting is evident. Certain operational risks (RBAC, credentials management, and temporary traffic-shift exposure) are typical for migrations and should be managed via standard controls.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 18, 2026, 09:34 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fclay-migration-deep-dive%2F@a2760b01e57ea17aca94b99f5e9fe64cd9c2393b