claude-code

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's core purpose matches its capabilities and official install source, so it is not malware. However, it materially increases risk by orchestrating a second autonomous agent, automating acceptance of trust and permission-bypass dialogs, and enabling transitive MCP/plugin tooling that can execute commands and access project data.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Apr 27, 2026, 07:09 AM
Package URL
pkg:socket/skills-sh/nousresearch%2Fhermes-agent%2Fclaude-code%2F@49d7945c5c1a1432fde7a3054d55f526bfe2eb70