claude-code
Warn
Audited by Socket on Jul 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's coding-assistant purpose is plausible, but its actual footprint relies on an unverifiable local runner and routes GitHub-authenticated actions through an undisclosed proxy endpoint. The delegation model is broader than necessary, and the proxy/token flow is not aligned with official GitHub API data paths.
Confidence: 84%Severity: 82%
Audit Metadata