claude-cli-agent

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's main purpose aligns with using Claude CLI for delegated analysis, and the external service appears to be Anthropic's official tooling, not a credential-harvesting proxy. But the documentation is internally inconsistent about dependencies, omits the essential `claude` dependency, and explicitly advises `--dangerously-skip-permissions`, which expands data exposure risk during autonomous analysis of local content.

Confidence: 91%Severity: 71%
Audit Metadata
Analyzed At
Apr 3, 2026, 06:10 PM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Fclaude-cli-agent%2F@282ba3eed69f13093610d24efa1f67899b91eaa5