claude-code-templates-cli

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core package source appears legitimate and proportionate for a Claude Code template manager, but the skill expands into transitive installation of agents/MCPs, uses mutable @latest execution, mixes publisher identities, and offers remote chat monitoring via tunnel. This is not confirmed malware, but it has meaningful security risk beyond a simple local configuration helper.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 16, 2026, 05:50 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fclaude-code-skills%2Fclaude-code-templates-cli%2F@c3cddc58ebcbc11391d82075bb433062c7d1a794
Security Audit — socket — claude-code-templates-cli