free-code-claude-cli

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s broad capability as a coding-agent fork is consistent with needing model credentials and local tool access, but the trust story is weak: it recommends executing a mutable raw GitHub installer from a personal account, offers an IPFS fallback, and encourages use of a modified CLI that strips guardrails while accepting cloud/API credentials. This is not confirmed malware, but it is a high-risk supply-chain and credential-forwarding scenario disproportionate to a normal skill install.

Confidence: 88%Severity: 84%
Audit Metadata
Analyzed At
Sep 12, 2026, 11:45 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Ftrending-skills%2Ffree-code-claude-cli%2F@f658db20e8089196643eef3667500435c19760bbedf9d22d28358ece43b4c390
Security Audit — socket — free-code-claude-cli