clade-install-auth
Fail
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [UNVERIFIABLE_DEPENDENCIES]: The instruction to install '@claude-ai/sdk' via npm is highly suspicious. The official Anthropic SDK for Node.js is '@anthropic-ai/sdk'. Directing users to unofficial packages with similar names is a common typosquatting tactic used to distribute malware.
- [REMOTE_CODE_EXECUTION]: By encouraging the installation and usage of the unofficial '@claude-ai/sdk' package, the skill facilitates the execution of unverified third-party code on the user's environment.
- [METADATA_POISONING]: The skill and its references consistently use the misspelled name 'clade' (e.g., 'clade-install-auth', 'clade-hello-world') instead of 'Claude'. This pattern of deceptive naming supports the assessment that the skill is intended to mislead users into using untrusted resources.
Recommendations
- AI detected serious security threats
Audit Metadata