skill-creator

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The SKILL.md fragment is documentation describing safe structure and workflows for Claude Code skills. There is no explicit malicious content in this file itself. The principal security concern is supply-chain and execution risk: the documentation encourages running local helper scripts (init_skill.py, validate_skill.py) under ~/.claude/skills while granting Bash and file-modification privileges. Because those scripts are not provided, they could contain arbitrary or malicious behavior. Recommend: do not execute referenced scripts until they have been code-reviewed; add provenance/signature checks for skill packages; adopt least-privilege execution (avoid unnecessary Bash privileges), and consider sandboxing validation or init tooling.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:48 PM
Package URL
pkg:socket/skills-sh/mauromedda%2Fagent-toolkit%2Fskill-creator%2F@41c2fbd771a46ab57ee74fff37070118c8b6ce9d