ccc-testing

Warn

Audited by Socket on Apr 1, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
qa/SKILL.md

SUSPICIOUS. The core browser-QA and bug-fixing capabilities broadly match the stated purpose, but the skill carries notable extra footprint: embedded telemetry, extensive home-directory state management, and a curl|bash Bun bootstrap. The Bun installer appears official, which reduces malware confidence, but the combination of autonomous code changes/commits and opaque telemetry keeps overall risk at medium.

Confidence: 85%Severity: 61%
AnomalyLOW
plankton-code-quality/SKILL.md

SUSPICIOUS: the skill is broadly consistent with a code-quality automation purpose, but it adds a nontrivial trust and execution surface by cloning a personal GitHub repo, running local setup/hooks, and silently spawning Claude subprocesses on every edit. No clear credential harvesting or off-purpose exfiltration is shown, so this is not malicious, but the install and autonomous execution model create medium security risk.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 1, 2026, 05:36 AM
Package URL
pkg:socket/skills-sh/KevinZai%2Fcc-commander%2Fccc-testing%2F@fa2d37ed5db1ed2ccf1d826382bc640073ca03af
Security Audit — socket — ccc-testing