claude-code-source-recovery

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's research/documentation purpose is mostly coherent, and the code examples themselves are not malicious, but the install path is not proportionate to a documentation skill. It relies on unofficial distribution sources—a Tencent mirror package tarball and a personal GitHub recovery repo—rather than Anthropic's verified channels, with no checksum or signature verification. That makes the main risk supply-chain trust, not confirmed malware or credential theft.

Confidence: 92%Severity: 78%
Audit Metadata
Analyzed At
Sep 12, 2026, 11:45 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Ftrending-skills%2Fclaude-code-source-recovery%2F@b5c9a6482cf70e137e84dca11801e3c29b67647ab68e09250d57b937d87e9a66
Security Audit — socket — claude-code-source-recovery