ccc-testing
Audited by Socket on Apr 1, 2026
2 alerts found:
Anomalyx2SUSPICIOUS. The core browser-QA and bug-fixing capabilities broadly match the stated purpose, but the skill carries notable extra footprint: embedded telemetry, extensive home-directory state management, and a curl|bash Bun bootstrap. The Bun installer appears official, which reduces malware confidence, but the combination of autonomous code changes/commits and opaque telemetry keeps overall risk at medium.
SUSPICIOUS: the skill is broadly consistent with a code-quality automation purpose, but it adds a nontrivial trust and execution surface by cloning a personal GitHub repo, running local setup/hooks, and silently spawning Claude subprocesses on every edit. No clear credential harvesting or off-purpose exfiltration is shown, so this is not malicious, but the install and autonomous execution model create medium security risk.