NYC

claude-agent-sdk

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The fragment presents a coherent, feature-rich SDK documentation/spec for Claude Agent SDK with structured outputs, plugins, hooks, MCP orchestration, and session management. There is no evidence of embedded malware or direct data exfiltration within the text. The primary risk lies in configuration and secret management in real deployments—for example, placeholders for tokens and headers could become leakage points if not guarded. With proper secret handling, code signing, and least-privilege enforcement, the material is benign and aligned with its intended usage.

Confidence: 67%Severity: 58%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:50 PM
Package URL
pkg:socket/skills-sh/ovachiever%2Fdroid-tings%2Fclaude-agent-sdk%2F@54a32f33c5e0b314c2cd0aa1a99a512bb53bb262