create-anyone

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core behavior matches its stated purpose, but that purpose is inherently sensitive: it clones personas from private communications and public content, then writes and can install runnable persona packs. The biggest concerns are broad access, indirect prompt injection from untrusted content, and reliance on additional unverified skills/CLIs; there is no clear evidence of outright credential theft or external exfiltration in the provided text.

Confidence: 81%Severity: 66%
Audit Metadata
Analyzed At
Apr 13, 2026, 01:25 AM
Package URL
pkg:socket/skills-sh/acnlabs%2FOpenPersona%2Fcreate-anyone%2F@a697d80d1887d38e48445094c725a5490db14d4d