skill-builder

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose broadly matches skill creation/import workflows, but the footprint is high-risk because it imports third-party skills, relies on only partially verified external tooling, supports custom model endpoints, and can promote untrusted content into active agent directories. The main concern is transitive trust and prompt-injection exposure rather than confirmed malware.

Confidence: 85%Severity: 84%
Audit Metadata
Analyzed At
Mar 21, 2026, 06:50 PM
Package URL
pkg:socket/skills-sh/lev-os%2Fagents%2Fskill-builder%2F@82f6ac54a443907d8b1904c58b6d97a5393f17fa