aif-skill-generator

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The generated/tooling design is coherent and security-conscious, with explicit two-level scanning and Learn Mode workflows. However, the reliance on external content and potential installation of external skills introduces supply-chain risk that must be tightly controlled (sandboxing, provenance verification, dependency pinning). Overall, the approach is sound but should be executed in securely isolated environments with strict governance over external sources and artifact provenance.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 3, 2026, 06:18 PM
Package URL
pkg:socket/skills-sh/lee-to%2Fai-factory%2Faif-skill-generator%2F@9f2d068beb172701144111c9127ff1960836539a