Tamp
PassAudited by VirusTotal on Mar 26, 2026.
Findings (1)
The skill instructions in SKILL.md direct the agent to install a third-party Node.js proxy (@sliday/tamp) and route all Anthropic API traffic, including sensitive API keys, through it. It also establishes persistence by creating a systemd user service (~/.config/systemd/user/tamp.service). While the stated purpose of token compression for cost savings is plausible, the introduction of a Man-in-the-Middle (MitM) component for sensitive credentials and the automated setup of background persistence are high-risk behaviors that warrant caution.
