claude-code-templates-cli
Warn
Audited by Socket on May 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core package source appears legitimate and proportionate for a Claude Code template manager, but the skill expands into transitive installation of agents/MCPs, uses mutable @latest execution, mixes publisher identities, and offers remote chat monitoring via tunnel. This is not confirmed malware, but it has meaningful security risk beyond a simple local configuration helper.
Confidence: 84%Severity: 58%
Audit Metadata