ghost-scan-code
Audited by Socket on Sep 29, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: the skill is largely coherent for a code-security scanner and does not show credential theft, hidden exfiltration, or malicious installers. The main risks are that it empowers agentic security scanning and introduces transitive trust in an unspecified `repo-context` skill; the official Claude CLI dependency appears legitimate and same-org, keeping this below malicious.
This is an orchestration script for dispatching Claude-based scanning workers over files and tracking unfinished work. It contains no clear malware or direct data exfiltration. The principal risks are prompt injection and path traversal through the unvalidated prompt argument, because the external claude process receives write-capable tools and follows a dynamically selected instruction file. The supplied code also contains an apparent syntax error at the final echo statement, which would prevent execution. Review and constrain prompt, path, and input values before use, and fix the unterminated quote.