build-giselle-agent

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose: it guides a developer through interviewing for an app use case, generates an agent prompt, integrates Giselle Agent SDK into a Next.js app, and wires up a chat route and UI using browser tools. The data flows rely on official Giselle services and registries, with credentials confined to standard environment variables (.env.local). No suspicious download/execute chains or credential harvesting patterns are evident. Overall, the skill is benign with moderate operational risk stemming from external API key handling and external service dependencies; ensure proper secret management and rotation, and validate any external data in the browser tool interactions.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 08:24 AM
Package URL
pkg:socket/skills-sh/giselles-ai%2Fagent-container%2Fbuild-giselle-agent%2F@8597cf6a22794e6a6db639b3ccb1e169031c600b