skill-creator

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md and accompanying templates describe a documentation-first meta-skill for authoring other skills. The content is largely benign: it contains templates, validation rules, and local command examples (mkdir, python3) but no network downloads, credential handling, or remote exfiltration. The primary operational risk is contextual: generated skills or helper scripts (discover_skills.py, validate_skill.py) — whose implementations are not included here — could introduce real security issues if they perform untrusted network operations, execute downloaded code, or improperly handle inputs. As presented, the document itself is low risk, but any actual script implementations referenced should be reviewed for unsafe behaviors before automated execution.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:37 PM
Package URL
pkg:socket/skills-sh/hyunjunjeon%2Fdeepagent-research-context-engineering%2Fskill-creator%2F@2a3b0078a7630fd1563c82af60e4eda45a200d7e