claude-context
Warn
Audited by Socket on Apr 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose is coherent, but the install instructions are internally inconsistent with the cited upstream project: it references a Zilliz repository while telling the agent to execute a different Anthropic-scoped package. Because the core behavior requires running external code that can read the whole codebase, this provenance mismatch materially raises supply-chain risk.
Confidence: 90%Severity: 76%
Audit Metadata