skill-creator

Warn

Audited by Socket on Apr 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall purpose is legitimate and most named endpoints are official or standard, but its footprint is overly broad: it searches local Claude config/plugin areas, fetches untrusted public content, recommends adopting/cloning other skills and MCPs, and encourages proactive installs and execution. This is not fundamentally incompatible with a skill-authoring tool, so it is not malicious, but the transitive-trust and indirect prompt-injection exposure make it higher risk than a narrowly scoped documentation or packaging skill.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Apr 5, 2026, 06:39 AM
Package URL
pkg:socket/skills-sh/daymade%2Fclaude-code-skills%2Fskill-creator%2F@005f69f35f19dfa5b1a9d116a930487591dd76bc