lobotomized-claude-code-update

Warn

Audited by Socket on Jun 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent with its stated purpose as a guarded updater for a customized Claude Code stack, and its Stage 1/Stage 2 approval flow is a meaningful safety control. However, it installs/updates and then builds and executes a personal-repo patcher that modifies the Claude binary, creating medium supply-chain and local execution risk even though the repo is public and purpose-aligned. No clear credential harvesting or exfiltration path is evident, so this is not confirmed malware, but it is riskier than a normal documentation or maintenance skill.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 17, 2026, 12:13 AM
Package URL
pkg:socket/skills-sh/tenequm%2Fskills%2Flobotomized-claude-code-update%2F@5dfa69500235c741c111a0fffba2c3e5db37dd640dc1053788279b5b562fc182
Security Audit — socket — lobotomized-claude-code-update