claude-cli-agent

Fail

Audited by Socket on Mar 6, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The file is a usage/operational guide for a Claude CLI sub-agent. It contains no direct malware or obfuscated payloads, but it recommends operational practices that substantially increase risk: piping large contexts (possible secrets) to a remote model, recommending the --dangerously-skip-permissions flag which removes human approval, and permitting Bash execution. These behaviors create a high potential for accidental data exfiltration and loss of human oversight. Remediation: remove or strongly qualify the --dangerously-skip-permissions recommendation, restrict or more tightly qualify Bash execution examples, add explicit instructions to sanitise inputs (strip secrets), chunk and scan content locally before sending, and require explicit human approval for sensitive transmissions.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 6, 2026, 03:26 AM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Fclaude-cli-agent%2F@42da16b0aeb495ee771046cde3279f4b9bcec39f