claude-code

Warn

Audited by Socket on Aug 22, 2026

1 alert found:

Anomaly
AnomalyLOW
references/cicd-gitlab.md

This CI/CD integration does not show explicit malicious code, but it materially increases supply-chain and governance risk: it sends repository/CI context to an external AI service and, critically, can automatically modify code and push commits back to the branch on CI failure. Treat this as a high-impact integrity and privacy review item, and enforce strict controls (branch protections, protected variables, runner permissions, human approval gates, and tight artifact access).

Confidence: 65%Severity: 62%
Audit Metadata
Analyzed At
Aug 22, 2026, 10:39 AM
Package URL
pkg:socket/skills-sh/kettleofketchup%2Fkettleofskills%2Fclaude-code%2F@9f0911ed01b4c26d2f01ed7da017e95b2644898c0f8f8ca991296ad50591d83a
Security Audit — socket — claude-code