aif-skill-generator
Fail
Audited by Socket on Mar 3, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
The generated/tooling design is coherent and security-conscious, with explicit two-level scanning and Learn Mode workflows. However, the reliance on external content and potential installation of external skills introduces supply-chain risk that must be tightly controlled (sandboxing, provenance verification, dependency pinning). Overall, the approach is sound but should be executed in securely isolated environments with strict governance over external sources and artifact provenance.
Confidence: 95%Severity: 90%
Audit Metadata