skill-creator

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Credential file access detected All findings: [HIGH] data_exfiltration: Credential file access detected (DE002) [AITech 8.2.3] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] The fragment is a benign, coherent documentation/specification for creating Agent Skills (SKILL.md). It aligns with its described purpose, has no evidence of malicious behavior, and does not request sensitive credentials or perform any data transmission. Overall security risk is low, with minor caution about ensuring future implementations derived from this guide follow the same security-conscious patterns.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 16, 2026, 11:17 AM
Package URL
pkg:socket/skills-sh/jkappers%2Fagent-skills%2Fskill-creator%2F@576e20ad4dd86b6706e9226829f4f8a5dcbcf6a4