free-code-claude-cli
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s broad capability as a coding-agent fork is consistent with needing model credentials and local tool access, but the trust story is weak: it recommends executing a mutable raw GitHub installer from a personal account, offers an IPFS fallback, and encourages use of a modified CLI that strips guardrails while accepting cloud/API credentials. This is not confirmed malware, but it is a high-risk supply-chain and credential-forwarding scenario disproportionate to a normal skill install.
Confidence: 88%Severity: 84%
Audit Metadata