awesome-claude-code-subagents
Warn
Audited by Socket on May 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is broadly consistent with a subagent marketplace/installer, but it installs additional agents/plugins, uses download-and-execute installation paths, and includes offensive-security subagents. The biggest issue is transitive trust: users are encouraged to load many external subagents that may act with Claude Code's permissions, and the stated publisher identity does not cleanly match the install source org.
Confidence: 89%Severity: 74%
Audit Metadata