understand-setup
Warn
Audited by Socket on Apr 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the purpose is coherent, but the skill relies on unverifiable local code and a second local project outside the skill without clear provenance. Main risk is execution trust and broad access to sensitive ~/.claude contents, not confirmed exfiltration or malware.
Confidence: 82%Severity: 74%
Audit Metadata