simplify-pr-claude
Warn
Audited by Socket on Apr 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated goal is plausible, but the skill mainly instructs the agent to fetch and run an unpinned external package with broad shell capability and limited transparency. This is a high supply-chain and transitive-trust risk, though not confirmed malware.
Confidence: 87%Severity: 81%
Audit Metadata