secure-ship
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose is coherent, but it is high-risk because it enables autonomous offensive testing and code-shipping actions, delegates to unseen local skills, and writes telemetry under ~/.claude/projects without explicit user confirmation. This looks more like a powerful vulnerable orchestration skill than confirmed malware.
Confidence: 87%Severity: 83%
Audit Metadata