github-code-search

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, but it expands trust to a third-party MCP service and mixes untrusted external content retrieval with local code execution guidance. Main concerns are transitive trust and indirect prompt-injection risk, not confirmed malware or credential theft.

Confidence: 83%Severity: 61%
Audit Metadata
Analyzed At
Mar 16, 2026, 03:13 PM
Package URL
pkg:socket/skills-sh/majiayu000%2Fclaude-skill-registry%2Fgithub-code-search%2F@899b7316c4593b0d41c661d036aa9e16b8dd1b3c