build-skill

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core behavior matches a skill-building assistant, but it introduces avoidable transitive trust by invoking a third-party skill and then persisting synthesized instructions into the user's skill directory. No direct credential theft, exfiltration, or malware behavior is visible, so this is better classified as medium security risk from transitive instruction supply chain rather than confirmed maliciousness.

Confidence: 83%Severity: 56%
Audit Metadata
Analyzed At
Apr 13, 2026, 04:27 PM
Package URL
pkg:socket/skills-sh/camacho%2Fai-skills%2Fbuild-skill%2F@d6bf61b6a4c717ca5eee4c787c9cc3dd37a567bb