skill-builder
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose broadly matches skill creation/import workflows, but the footprint is high-risk because it imports third-party skills, relies on only partially verified external tooling, supports custom model endpoints, and can promote untrusted content into active agent directories. The main concern is transitive trust and prompt-injection exposure rather than confirmed malware.
Confidence: 85%Severity: 84%
Audit Metadata