agent-skill-creator

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core purpose is plausible, but its actual footprint is too autonomous and expansive. It ingests untrusted external content, generates executable artifacts, installs skills into agent directories, and can create/push remote repos or registries, creating high transitive-trust and prompt-injection risk. Install provenance is same-publisher but still uses mutable remote execution, so this is best classified as high-risk vulnerable behavior rather than confirmed malware.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Mar 27, 2026, 03:12 AM
Package URL
pkg:socket/skills-sh/FrancyJGLisboa%2Fagent-skill-creator%2Fagent-skill-creator%2F@0e80457578123ef1f244abafeb21d811a7641246