claude-blog-brain
Audited by Socket on Jul 25, 2026
3 alerts found:
Anomalyx2SecuritySUSPICIOUS: the skill’s capabilities mostly match its stated image-generation purpose, but it depends on a community MCP package that receives the user’s Google AI API key. This is a coherent developer workflow, not clear malware, yet the credential-forwarding and third-party trust boundary make it medium risk.
SUSPICIOUS: The core blog-rewrite purpose is broadly coherent, and there are no external installers, credential grabs, or clear exfiltration paths. The main risks are evasion-oriented anti-detection instructions, processing untrusted web content while retaining write/exec capability, and reliance on unreviewed local scripts/sub-skills whose behavior is not visible here.
SUSPICIOUS. The skill’s stated SEO-analysis purpose and official DataForSEO endpoints are coherent, and local mode is low risk. However, API mode relies on an unidentified local wrapper that is not provenance-verifiable and would receive reusable credentials, creating a significant supply-chain and credential-forwarding risk disproportionate to an otherwise straightforward analysis skill.