clade-install-auth
Warn
Audited by Socket on Aug 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's stated purpose is legitimate, and the Python path is consistent with Anthropic's official SDK, but the Node.js instructions are internally inconsistent and point to a non-official package name while encouraging use of ANTHROPIC_API_KEY with it. That supply-chain mismatch is disproportionate for an auth/install skill and creates credential-forwarding risk, even without confirmed malware.
Confidence: 94%Severity: 84%
Audit Metadata