aif-skill-generator

Fail

Audited by Socket on Apr 3, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, and its use of official ecosystem CLIs is plausible, but it combines arbitrary web ingestion, file generation, shell execution, and explicit third-party skill installation. The main risk is transitive trust and prompt-injection exposure from external skills/URLs rather than clear malicious intent.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Apr 3, 2026, 09:58 AM
Package URL
pkg:socket/skills-sh/lee-to%2Fai-factory%2Faif-skill-generator%2F@af2361c6c96267425f75d6a429911f89bf30851d