claude-code-source-recovery
Fail
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone a repository from a personal GitHub account (
ponponon/claude_code_src) that is not associated with a trusted organization. - [REMOTE_CODE_EXECUTION]: The skill recommends performing a global installation of a package directly from a URL hosted on a third-party mirror (
mirrors.cloud.tencent.com). While the mirror host is a well-known service, installing recovered versions of sensitive tools from unverified sources facilitates the execution of potentially modified code. - [COMMAND_EXECUTION]: The skill provides instructions to execute several high-risk commands, including global package installations, repository cloning, and local compilation of recovered source code.
- [DATA_EXFILTRATION]: The skill identifies the local file system path where sensitive Anthropic API credentials are stored (
~/.claude/credentials.json) and provides code logic for reading and writing these secrets.
Recommendations
- AI detected serious security threats
Audit Metadata