clade-install-auth

Warn

Audited by Socket on Aug 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's stated purpose is legitimate, and the Python path is consistent with Anthropic's official SDK, but the Node.js instructions are internally inconsistent and point to a non-official package name while encouraging use of ANTHROPIC_API_KEY with it. That supply-chain mismatch is disproportionate for an auth/install skill and creates credential-forwarding risk, even without confirmed malware.

Confidence: 94%Severity: 84%
Audit Metadata
Analyzed At
Aug 21, 2026, 12:59 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fclade-install-auth%2F@6622694ab2d71624cd27282138717aa36dbc40b66e1666c09a544b86423c7d98
Security Audit — socket — clade-install-auth