clone

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The described steps match the apparent purpose (cloning a conversation) and are functionally reasonable. The main security concern is that the workflow discovers and executes an arbitrary local script under ~/.claude without provenance checks or user confirmation, creating a high-risk local supply-chain/hijack vector that can lead to arbitrary code execution and potential data exfiltration. No direct evidence of network-based malware or hard-coded secrets exists in the snippet itself, but the execution sink makes the overall flow hazardous unless mitigated by verification or explicit user inspection.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 02:30 AM
Package URL
pkg:socket/skills-sh/ykdojo%2Fclaude-code-tips%2Fclone%2F@4ddb122b40d373398492ae1562afd84f313a0dc1