build-giselle-agent
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileThe skill's footprint is coherent with its stated purpose: it guides a developer through interviewing for an app use case, generates an agent prompt, integrates Giselle Agent SDK into a Next.js app, and wires up a chat route and UI using browser tools. The data flows rely on official Giselle services and registries, with credentials confined to standard environment variables (.env.local). No suspicious download/execute chains or credential harvesting patterns are evident. Overall, the skill is benign with moderate operational risk stemming from external API key handling and external service dependencies; ensure proper secret management and rotation, and validate any external data in the browser tool interactions.