quickcreator-skill-builder

Fail

Audited by Socket on Feb 26, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The QuickCreator Skill Builder fragment presents a coherent workflow for connecting a local agent to QuickCreator via a Developer Key and an MCP-based integration. However, credential handling patterns (PROMPT-for-key, environment-variable propagation, and multi-path local config writes) introduce non-trivial security and privacy risks, particularly on shared machines or in logs. The use of a development API endpoint further elevates risk if used in production contexts. Mitigations should include: scoped, short-lived tokens; encryption of credentials at rest; explicit per-action user consent; minimal local persistence; clearer separation between dev/prod endpoints; and explicit rotation/revocation mechanisms. Overall, treat this as moderately risky with strong remediation requirements before broader deployment.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 26, 2026, 04:56 AM
Package URL
pkg:socket/skills-sh/kycloudtech%2Fquickcreator-skills%2Fquickcreator-skill-builder%2F@514b6ea8c6542c9ff9990fbe204bfd297e4f6458