install

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent and mostly local, but trust is weakened by unverifiable local toolkit scripts, unseen Python dependencies, and a likely publisher mismatch in the suggested Context7 MCP install command. No clear credential theft or exfiltration is present, so this looks more like medium supply-chain and trust risk than malware.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 12:37 PM
Package URL
pkg:socket/skills-sh/notque%2Fclaude-code-toolkit%2Finstall%2F@b6d347f44c78e85825b1a5967fd99bbb48b44dab