ccp

Warn

Audited by Socket on May 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches profile management, but the skill’s main capability is installing and activating external skills from GitHub/registries through an unspecified `ccp` CLI. The transitive trust chain and missing provenance for the core tool make the footprint higher risk than a normal local config manager.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
May 5, 2026, 02:13 PM
Package URL
pkg:socket/skills-sh/samhvw8%2Fdotfiles%2Fccp%2F@0c9684d55bb91e7684cc98742c554727f46b137f
Security Audit — socket — ccp