claude-blog-brain

Warn

Audited by Socket on Jul 25, 2026

3 alerts found:

Anomalyx2Security
AnomalyLOW
.raw/sources/claude-blog-skill/skills/blog-image/SKILL.md

SUSPICIOUS: the skill’s capabilities mostly match its stated image-generation purpose, but it depends on a community MCP package that receives the user’s Google AI API key. This is a coherent developer workflow, not clear malware, yet the credential-forwarding and third-party trust boundary make it medium risk.

Confidence: 84%Severity: 63%
AnomalyLOW
.raw/sources/claude-blog-skill/skills/blog-rewrite/SKILL.md

SUSPICIOUS: The core blog-rewrite purpose is broadly coherent, and there are no external installers, credential grabs, or clear exfiltration paths. The main risks are evasion-oriented anti-detection instructions, processing untrusted web content while retaining write/exec capability, and reliance on unreviewed local scripts/sub-skills whose behavior is not visible here.

Confidence: 83%Severity: 58%
SecurityMEDIUM
.raw/sources/claude-blog-skill/skills/blog-cannibalization/SKILL.md

SUSPICIOUS. The skill’s stated SEO-analysis purpose and official DataForSEO endpoints are coherent, and local mode is low risk. However, API mode relies on an unidentified local wrapper that is not provenance-verifiable and would receive reusable credentials, creating a significant supply-chain and credential-forwarding risk disproportionate to an otherwise straightforward analysis skill.

Confidence: 86%Severity: 80%
Audit Metadata
Analyzed At
Jul 25, 2026, 09:34 AM
Package URL
pkg:socket/skills-sh/AgriciDaniel%2Fclaude-blog%2Fclaude-blog-brain%2F@3a68c222840971951d354f940e468992bba167d7f0f38cc46e6efab4e2d4d39f
Security Audit — socket — claude-blog-brain