ai-shifu-course-creator
Warn
Audited by Socket on Apr 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s authoring and platform-management scope matches its stated purpose, and the service endpoints look same-org. However, deployment depends on an undocumented local CLI that receives SHIFU_TOKEN and can perform high-impact live publishing and management actions, creating medium-high trust and autonomy risk despite no clear evidence of malicious exfiltration.
Confidence: 85%Severity: 72%
Audit Metadata