create-agent

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill represents a coherent, structured approach to authoring agent configurations as markdown with YAML frontmatter. Its footprint is proportionate to a developer tooling task: creating and persisting agent definitions and prompts. However, there are minor concerns about input validation for frontmatter fields, lack of explicit access-control/sandboxing for file writes, and absence of a formal schema to prevent invalid tool/model combinations. Overall, it is BENIGN with moderate risk due to potential file write operations and the need for basic validation; no credential or network data handling is evident, and data remains within a local repository/plugin ecosystem.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 06:50 AM
Package URL
pkg:socket/skills-sh/jpoutrin%2Fproduct-forge%2Fcreate-agent%2F@57942368bed4748bdc27f65ddea33f5f39fc201a