sync-template
Warn
Audited by Socket on Jun 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core sync behavior is coherent, but the skill's footprint goes beyond template synchronization by automatically installing fetched files as project and global Claude skills/commands. Trust is further weakened because content is fetched from a mutable personal GitHub repo by branch name rather than pinned commits or signed releases. No direct credential theft is evident, but the transitive skill installation and global file writes make this higher risk than a normal template-sync skill.
Confidence: 91%Severity: 78%
Audit Metadata