create-anyone
Warn
Audited by Socket on Apr 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's core behavior matches its stated purpose, but that purpose is inherently sensitive: it clones personas from private communications and public content, then writes and can install runnable persona packs. The biggest concerns are broad access, indirect prompt injection from untrusted content, and reliance on additional unverified skills/CLIs; there is no clear evidence of outright credential theft or external exfiltration in the provided text.
Confidence: 81%Severity: 66%
Audit Metadata