r07-indirect
Warn
Audited by Socket on Apr 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's behavior is coherent with its stated purpose, but that purpose is to persistently modify Claude's instruction memory. There is no download, exfiltration, or credential access, yet writing to `~/.claude/CLAUDE.md` is a high-impact persistence action that can silently affect future agent behavior.
Confidence: 93%Severity: 74%
Audit Metadata