claude-code
Warn
Audited by Socket on Apr 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's core purpose matches its capabilities and official install source, so it is not malware. However, it materially increases risk by orchestrating a second autonomous agent, automating acceptance of trust and permission-bypass dialogs, and enabling transitive MCP/plugin tooling that can execute commands and access project data.
Confidence: 89%Severity: 72%
Audit Metadata