plugin-creation

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The plugin-creation skill description is internally consistent with its stated purpose of scaffolding Claude Code plugins. It uses local templates and initialization scripts, maintains a clearly defined plugin structure, and does not reveal external or credential-related data flows. The footprint is proportionate to its goals. The primary risk area is potential command/shell content embedded in generated SKILL/COMMAND definitions if those outputs are later executed by Claude without proper input validation. Overall, the risk is low to moderate (benign to suspicious in edge cases) and the capability appears appropriate for its stated purpose.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 12:32 AM
Package URL
pkg:socket/skills-sh/camoa%2Fclaude-skills%2Fplugin-creation%2F@2a5cf6c73212d3d02b69e6f4ce668527e32889d8