provider-switch

Warn

Audited by Socket on Aug 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s main behavior is coherent with provider switching, and the documented provider endpoints appear official, but it persistently stores API keys in ~/.zshrc, forwards credentials to third-party providers/aggregators, and includes a hidden update workflow with web-research plus file-editing capabilities. This looks more like a high-risk configuration helper than confirmed malware.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Aug 14, 2026, 06:25 PM
Package URL
pkg:socket/skills-sh/kochetkov-ma%2Fclaude-brewcode%2Fprovider-switch%2F@5a2e48f7c4630e276803bab11142d63d611b4477c459608e1b8782c5feca2507
Security Audit — socket — provider-switch