skill-builder

Fail

Audited by Socket on Mar 14, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill's main purpose is coherent, and its primary dependency appears to be an official PyPI/GitHub project, but it meaningfully expands trust by importing third-party skills and by processing untrusted external content before writing into agent skill directories. The biggest risks are transitive skill installation and prompt-injection-through-content, not confirmed malware.

Confidence: 86%Severity: 66%
Audit Metadata
Analyzed At
Mar 14, 2026, 09:26 AM
Package URL
pkg:socket/skills-sh/lev-os%2Fagents%2Fskill-builder%2F@2d96e75079d41ac5a73829c8f97e79a0bae76515