skill-creator

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Mostly aligned with its stated purpose: creating and managing skills. The main concerns are transitive trust in other skills, external-content prompt injection exposure, and an unspecified upload endpoint for the skill library. This looks suspicious rather than malicious because the risky capabilities fit the workflow, but the trust and data-flow boundaries are not fully disclosed.

Confidence: 86%Severity: 62%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:29 AM
Package URL
pkg:socket/skills-sh/dtyq%2Fmagic%2Fskill-creator%2F@a8b1949ff94fe63c24b7dd9e7d15ca28e3a788c1