claude-settings-audit
Warn
Audited by Socket on Apr 9, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core local-repo auditing behavior is coherent and mostly read-only, but the skill exceeds that purpose by recommending transitive skills, broad GitHub API permissioning, and MCP integrations that introduce external code execution and credential forwarding. Not confirmed malicious, but scope and data-flow expansion make it medium risk.
Confidence: 84%Severity: 63%
Audit Metadata