claude-settings-audit
Warn
Audited by Socket on Jul 9, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core repo-audit behavior is coherent and mostly read-only, but the skill reaches beyond that scope by recommending broad gh API access, many additional skills, and a Linear MCP setup that appears inconsistent with current official Linear documentation. Main concern is credential forwarding and supply-chain trust around the npm-based Linear MCP suggestion, not confirmed malware.
Confidence: 87%Severity: 64%
Audit Metadata