claude-authenticity
Warn
Audited by Socket on Jun 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core endpoint-testing behavior is coherent and the install path is benign, but the skill intentionally forwards API keys to arbitrary endpoints and includes explicit system-prompt extraction logic. This is not confirmed malware, yet it is a medium-high risk auditing tool that can expose credentials and hidden instructions when used against untrusted providers.
Confidence: 100%Severity: 60%
Audit Metadata