sprite

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The skill is internally consistent with its stated purpose, but that purpose itself requires high-trust behavior: extracting a local Claude OAuth token, forwarding it to a remote Sprites.dev VM, and letting the agent control an InnerClaude session that can approve actions interactively. No clear signs of malware or deceptive exfiltration were found, and installer evidence appears same-org/official, but the credential-forwarding and autonomous remote-operation footprint make this a medium-high security risk skill.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:34 PM
Package URL
pkg:socket/skills-sh/spm1001%2Fclaude-suite%2Fsprite%2F@b1ae0d944bd0445e4b3442a68865742c1621522a
Security Audit — socket — sprite