skill-creator
Warn
Audited by Socket on Apr 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s overall purpose is legitimate and most named endpoints are official or standard, but its footprint is overly broad: it searches local Claude config/plugin areas, fetches untrusted public content, recommends adopting/cloning other skills and MCPs, and encourages proactive installs and execution. This is not fundamentally incompatible with a skill-authoring tool, so it is not malicious, but the transitive-trust and indirect prompt-injection exposure make it higher risk than a narrowly scoped documentation or packaging skill.
Confidence: 87%Severity: 68%
Audit Metadata