moai-foundation-claude

Warn

Audited by Socket on Mar 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The code fragment is a coherent, well-scoped manifest for a Claude Code authoring kit. It aligns with its stated purpose, references standard plugin/skill/sub-agent patterns, and does not embed credential handling, network calls, or exploit vectors. While its operational use could introduce supply-chain risks if misconfigured (e.g., installing untrusted plugins or sub-agents), the fragment itself does not exhibit malicious behavior and remains within a benign, capability-defining footprint. Treat as SUSPICIOUS-to-BENIGN depending on downstream usage; in isolation it is benign but warrants standard secure governance for installations and dependencies.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 2, 2026, 07:54 PM
Package URL
pkg:socket/skills-sh/modu-ai%2Fmoai-adk%2Fmoai-foundation-claude%2F@39f8f637bd6019fd0ea33619ec20d685fa9d1221