kage-bunshin

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose matches its capabilities, but its footprint is high-risk because it spawns parallel Claude sessions with inherited project/user capabilities and explicitly disables permission prompts via --dangerously-skip-permissions. There is no obvious external credential exfiltration path or malicious installer, but the autonomous multi-agent control model materially increases execution and prompt-injection risk.

Confidence: 87%Severity: 79%
Audit Metadata
Analyzed At
Mar 29, 2026, 08:41 AM
Package URL
pkg:socket/skills-sh/Jamie-BitFlight%2Fclaude_skills%2Fkage-bunshin%2F@8c5458d19864f7204349f4d8e1908a4104c1ac45