skillopt-lite
Audited by Socket on Aug 27, 2026
2 alerts found:
Anomalyx2SUSPICIOUS. The skill's main capabilities fit its stated optimization purpose, but it accesses broad local transcripts, routes evaluation through an opaque CLI/proxy, and forwards a real API key into unverified local sandbox tooling. Not clearly malicious, yet the install/execution trust and data-flow transparency are weaker than ideal for a skill that reprocesses historical user interactions.
The fragment does not show clear malicious intent or common supply-chain malware indicators. It is a local LLM benchmarking utility with legitimate filesystem, subprocess, and network behavior. Review is warranted before use with sensitive Claude logs or untrusted --base/--factory/--staged inputs: prompts and outputs can leave the host, and rollout executes a shell script with inherited environment privileges. Use a trusted endpoint and factory repository, restrict permissions, and treat mined datasets as sensitive.