manage

Warn

Audited by Socket on Jul 30, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose matches its Kindle/Calibre capabilities, but its trust model is weak. The main concerns are transitive delegation to another skill and dependence on mixed-source DRM-removal binaries/ZIPs and tutorials, some outside official vendor channels. No strong evidence of credential theft or exfiltration appears in this router skill, but the supply-chain and host-mutation footprint are high for a consumer ebook workflow.

Confidence: 86%Severity: 76%
AnomalyLOW
references/workflow.md

No direct evidence of malware or an explicit sabotage/backdoor mechanism is present in the provided fragment (it is an instruction/workflow text, not executable code). However, from a supply-chain security standpoint, it is still high-risk because it downloads and executes multiple third-party binaries (Kindle installer, DeDRM_tools, Kindle Key Finder) and modifies system firewall/ACL settings, while writing sensitive decrypted key material to local Calibre configuration. The workflow claims hash verification against references/versions.md and includes guards for placeholder values, which reduces some risk, but dynamic tag selection (when gh is available) and the general “download-then-execute” pattern remain notable concerns. Additional context (the referenced scripts/binaries/plugin code) would be required for a definitive malware verdict.

Confidence: 55%Severity: 55%
Audit Metadata
Analyzed At
Jul 30, 2026, 07:57 PM
Package URL
pkg:socket/skills-sh/melodic-software%2Fclaude-code-plugins%2Fmanage%2F@82b435ab3d5ba00c108f1998728405f4461a70e45b0675b7ca3616e444fa7396
Security Audit — socket — manage