Claude Code Sdk
PassAudited by VirusTotal on May 10, 2026.
Findings (1)
The skill acts as a wrapper for an external SDK (@anthropic-ai/claude-agent-sdk) and grants the sub-agent broad capabilities including full 'Bash' access and file system manipulation. The SKILL.md file contains instructions that command the primary AI agent to delegate all coding tasks and autonomously resolve environment or permission issues ('自主修复'), which effectively encourages the agent to bypass system constraints. While no explicit malicious payloads or exfiltration logic are present in run_claude.mjs, the combination of broad tool permissions and instructions to prioritize this tool for all tasks creates a significant risk for unauthorized system modification.
