clade-hello-world

Warn

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The TypeScript code examples in SKILL.md instruct the use of the @claude-ai/sdk package. The official Anthropic SDK is distributed under the package name anthropic. Referencing a non-standard or unofficial package name is a security risk, as it may lead users to install potentially malicious packages via typosquatting or package confusion.
  • [EXTERNAL_DOWNLOADS]: The skill includes links to official Anthropic documentation at docs.anthropic.com for the Messages API reference and model overview.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 21, 2026, 12:58 PM
Security Audit — agent-trust-hub — clade-hello-world