skill-builder
Fail
Audited by Socket on Mar 14, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS: the skill's main purpose is coherent, and its primary dependency appears to be an official PyPI/GitHub project, but it meaningfully expands trust by importing third-party skills and by processing untrusted external content before writing into agent skill directories. The biggest risks are transitive skill installation and prompt-injection-through-content, not confirmed malware.
Confidence: 86%Severity: 66%
Audit Metadata