claude-api

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
java/managed-agents/README.md

No clear evidence of intentional malware/backdoor behavior is visible in this fragment. However, it demonstrates high-risk secret handling by embedding GitHub authorization tokens directly in source code and includes a brittle token-rotation flow that updates the first listed repository without validating the intended target. These issues materially increase the likelihood of credential leakage and accidental mis-rotation, which are serious supply-chain and operational security concerns.

Confidence: 60%Severity: 65%
Audit Metadata
Analyzed At
Aug 26, 2026, 09:10 AM
Package URL
pkg:socket/skills-sh/warpdotdev%2Fwarp%2Fclaude-api%2F@3ef1c5149b02a0ee12ffc68f5f154ecf6692c369535b767c9de69f113171d70f
Security Audit — socket — claude-api