claude-settings-audit

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core repository-audit behavior is coherent and mostly read-only, but the skill goes beyond simple auditing by recommending transitive installation of many other skills and optional MCP integrations. The main concerns are trust expansion, credential forwarding in the Linear npx MCP example, and an only partially verified Sentry MCP endpoint. This is not confirmed malware, but it has meaningful security risk beyond a narrowly scoped settings auditor.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 04:40 PM
Package URL
pkg:socket/skills-sh/getsentry%2Fsentry-skills%2Fclaude-settings-audit%2F@6c535ac41e7ad57fa57965b5b965ecb9d704f224