advanced-features-2025
Warn
Audited by Socket on Mar 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is mostly a legitimate documentation guide for Claude Code features, but it expands trust through automatic hooks, team plugin distribution, and MCP examples that forward credentials to executed subprocesses. The main concerns are transitive plugin installation and mutable npx-based MCP execution, especially the inconsistent Stripe package example; this is more risky than malicious.
Confidence: 87%Severity: 61%
Audit Metadata