command-creator

Warn

Audited by Socket on Mar 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The document itself is a benign specification describing how to author Pi and OpenCode command templates. However, the OpenCode features it documents (arbitrary shell output injection via backticks and arbitrary file inclusion via @) create high-risk data exfiltration and command-execution vectors if the agent/runtime executes template content without strict safeguards. The inconsistent frontmatter (disable-model-invocation: true) adds confusion about whether remote model invocation is actually allowed. Overall this skill specification increases attack surface: malicious or careless templates can read sensitive files and send their contents to external models, or run arbitrary shell commands. The fragment is not itself malware, but it enables dangerous behaviors and should be treated as medium-high risk unless the runtime enforces sandboxing, whitelisting, and explicit user consent for shell/file inclusions.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 2, 2026, 02:45 AM
Package URL
pkg:socket/skills-sh/devskale%2Fskale-skills%2Fcommand-creator%2F@2477360aeef9dd2c534bfa629bf00223d4785ad8