cc-connect

Warn

Audited by Socket on Jul 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s functionality broadly matches its stated purpose, and install provenance is mostly legitimate via npm and a matching public repo. However, its footprint is high-risk by design: it forwards messaging credentials to an external CLI, exposes a local coding agent to remote prompting from chat, and supports autonomous scheduled/public messaging actions. This looks more like a powerful remote-control bridge than overt malware, but it should be treated as high operational risk.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Jul 7, 2026, 10:57 AM
Package URL
pkg:socket/skills-sh/TerminalSkills%2Fskills%2Fcc-connect%2F@5c045300c62036be72cb2a5a704a981fd1c2da773d8da78d3a50964c83b485e8
Security Audit — socket — cc-connect