push-notifications
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS rather than malicious. The core push-notification capabilities and credential needs largely match the stated purpose, and install sources are mostly official or well-known. The main risks are autonomous execution without approval, transitive skill invocation, broad file modification, and out-of-scope telemetry writes to ~/.claude/projects.
Confidence: 89%Severity: 68%
Audit Metadata