vector-cluster

Warn

Audited by Socket on Jun 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is not overtly malicious, but its actual footprint is inconsistent with its stated vector/namespace purpose and it executes a mismatched external npm package version via npx. Main concern is install/provenance ambiguity and purpose-capability misalignment, not confirmed credential theft or exfiltration.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 13, 2026, 01:24 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fclaude-flow%2Fvector-cluster%2F@1a593dba8d058c11714c1c7794d5510ae0cf907212ba44b595fe34a962084dfe
Security Audit — socket — vector-cluster