claude-peers
Audited by Socket on Jul 20, 2026
2 alerts found:
SecurityAnomalyNo clear evidence of classic supply-chain malware (e.g., obfuscated payloads, eval/Function execution, remote exfiltration to external domains, crypto-mining, or backdoor persistence mechanisms). However, this broker has inherently dangerous control capabilities: unauthenticated endpoints allow arbitrary callers to register peers and invoke /kill-peer, which performs process termination via process.kill and system 'ps'. If the unix socket permissions are misconfigured or TCP fallback is enabled, this becomes a high-impact denial-of-service/operational sabotage vector.
SUSPICIOUS: the core messaging purpose is coherent with local socket, SQLite, and peer coordination features, but the skill's footprint is elevated by session-kill capability and guidance to disable Codex sandbox protections. No clear credential harvesting or external exfiltration is shown, yet the unverified local CLI provenance and reduced security controls make this higher-risk than a normal coordination skill.