auth-provider
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The core auth-integration behavior is mostly coherent and uses standard package registries, but the skill is high-risk because it operates in fully autonomous mode, can install and mutate a project without confirmation, writes unrelated telemetry to ~/.claude/projects/, and encourages follow-on execution of other skills. No clear credential theft or malicious exfiltration is present, so this is not confirmed malware.
Confidence: 87%Severity: 73%
Audit Metadata