ccc-security
Audited by Socket on Apr 1, 2026
4 alerts found:
AnomalySecurityx3SUSPICIOUS. The top-level skill is mostly a router and is broadly aligned with a security-audit purpose, but it asks the agent to operate across a full security domain and to load unseen sub-skills. With no concrete install steps, credential handling, or data flows shown here, there is no evidence of confirmed malware; the main risk is transitive trust and the high-impact nature of downstream security capabilities.
The skill is internally consistent with its stated purpose and shows no installer, credential-harvesting, or exfiltration behavior. However, it equips the agent to perform offensive security testing against applications, so it should be treated as a high-risk security capability rather than malware.
SUSPICIOUS: the skill is internally consistent and not malicious, but it is a security/exploit-oriented skill that equips an AI agent to probe applications for vulnerabilities. There are no credential-harvesting, exfiltration, or supply-chain concerns; the main risk is granting offensive security testing capability to an agent.
BENIGN for internal consistency but HIGH-RISK as a security capability: the skill's actions match its stated purpose, uses only local search/reporting plus optional official CodeQL, and does not request credentials or exfiltrate data. The main concern is that it gives an AI agent offensive-style vulnerability discovery capability across a codebase.