advanced-features-2025

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly a legitimate documentation guide for Claude Code features, but it expands trust through automatic hooks, team plugin distribution, and MCP examples that forward credentials to executed subprocesses. The main concerns are transitive plugin installation and mutable npx-based MCP execution, especially the inconsistent Stripe package example; this is more risky than malicious.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Mar 20, 2026, 12:09 PM
Package URL
pkg:socket/skills-sh/josiahsiegel%2Fclaude-plugin-marketplace%2Fadvanced-features-2025%2F@579f7b0ee3e64f29739afc704c4cbc33b80ed1f8