claude-code-plugin-hacker

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent with local plugin debugging, and it does not fetch remote payloads or route data to third-party services. However, it instructs the agent to execute plugin-defined commands via eval, rebuild third-party dependencies, and make bulk destructive edits/removals in cached plugin code, which creates meaningful local code-execution and integrity risk even though the behavior broadly fits the stated purpose.

Confidence: 89%Severity: 61%
Audit Metadata
Analyzed At
May 15, 2026, 03:29 AM
Package URL
pkg:socket/skills-sh/laststance%2Fskills%2Fclaude-code-plugin-hacker%2F@8a1bdbb94d0824aed56a15375d832cfdbfe7b11e
Security Audit — socket — claude-code-plugin-hacker