clerk-incident-runbook

Warn

Audited by Socket on Mar 13, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is a Clerk incident runbook, but the granted shell permissions are much broader than necessary for visible documentation and could enable arbitrary downloads or package execution. No malicious exfiltration or fake Clerk endpoints are shown, yet the hidden implementation guide and wildcard npm/curl access make the skill higher-risk than a normal procedural runbook.

Confidence: 84%Severity: 62%
AnomalyLOW
references/implementation-guide.md

The code is an operational runbook with example scripts for managing Clerk incidents. It does not contain signs of malware or obfuscated malicious payloads. However, it includes high-risk administrative operations (an environment-driven authentication bypass, bulk upserts, session revocation, and account bans) that, if misconfigured or executed by an unauthorized actor, could cause serious security and availability issues. These are legitimate but dangerous features and should be protected with strict controls and safeguards.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Mar 13, 2026, 11:52 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fclerk-incident-runbook%2F@36d6c09ad04d328e715f07ac654dba41972e63d1