claude-code-showcase

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but its trust boundary is not. Local hooks and Claude Code project setup are proportionate, yet the examples forward multiple secrets into npx-installed packages whose Anthropic ownership could not be verified, and some package names appear inconsistent with Anthropic’s official docs. Scheduled GitHub Actions also enable autonomous commenting and auto-committing. Main risk is supply-chain and credential forwarding, not confirmed malware.

Confidence: 88%Severity: 84%
Audit Metadata
Analyzed At
May 17, 2026, 07:29 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fclaude-code-skills%2Fclaude-code-showcase%2F@b804e3f26b56909ac1e03ab7bc97c9ebf72ba9e7
Security Audit — socket — claude-code-showcase