ai-shifu-course-creator

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s authoring and platform-management scope matches its stated purpose, and the service endpoints look same-org. However, deployment depends on an undocumented local CLI that receives SHIFU_TOKEN and can perform high-impact live publishing and management actions, creating medium-high trust and autonomy risk despite no clear evidence of malicious exfiltration.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
Apr 13, 2026, 12:22 PM
Package URL
pkg:socket/skills-sh/ai-shifu%2Fskills%2Fai-shifu-course-creator%2F@ac30017fe517155a86a20e2b5605ecec1a143479