claude-agent-sdk
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is mostly a documentation/tutorial skill and its capabilities fit its stated purpose, but the package/install details appear inconsistent with Anthropic's official SDK naming, and it includes npx-based MCP execution examples. This looks more like unreliable or hallucinated SDK guidance than confirmed malware, but the install-trust issues and powerful agent patterns create medium risk.
Confidence: 89%Severity: 57%
Audit Metadata