kage-bunshin
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose matches its capabilities, but its footprint is high-risk because it spawns parallel Claude sessions with inherited project/user capabilities and explicitly disables permission prompts via --dangerously-skip-permissions. There is no obvious external credential exfiltration path or malicious installer, but the autonomous multi-agent control model materially increases execution and prompt-injection risk.
Confidence: 87%Severity: 79%
Audit Metadata