cc-claude

Warn

Audited by Socket on Jun 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is coherent, and the default DeepSeek endpoint is officially compatible, but the execution path relies on an unverified local shell wrapper and exposes API keys by collecting them in-chat and forwarding them on the command line. This looks more like risky credential handling and moderate supply-chain trust issues than confirmed malware.

Confidence: 85%Severity: 69%
Audit Metadata
Analyzed At
Jun 19, 2026, 10:57 AM
Package URL
pkg:socket/skills-sh/gitByEOS%2Fopen-part-skills%2Fcc-claude%2F@38e87137aebdd94f37589df1bd68d2d6396e9702e1accc5ee97726d154f4f976
Security Audit — socket — cc-claude