glossary-management

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is internally consistent with its stated purpose: managing a centralized glossary and syncing it to Vale vocabularies. There are no references to remote downloads, third-party intermediaries, or explicit data exfiltration. The main supply-chain/security risks are operational: it scans many projects under the user's home (increasing attack surface) and executes local hook scripts with bun — if those hook files are malicious or compromised they can perform arbitrary actions. Recommended mitigations: audit and lock down hook scripts and ~/.claude tools before running, run commands in a controlled environment, and avoid blindly executing rm -rf or bun scripts from unverified locations. Overall, not obviously malicious but moderate caution is warranted due to the execution of local scripts and broad filesystem access.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 03:55 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fglossary-management%2F@adb3b31222900cb314c84138a0c317f8ab2a586c