create-agent-skills

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
advanced.md

No direct malware behavior (e.g., backdoor, credential theft, or external exfiltration endpoints) is evident in the provided fragment. However, it documents a high-risk capability: dynamic shell/CLI command execution via `!` + `` `command` `` and embeds command outputs into the agent’s prompt, plus it logs unvalidated caller-provided arguments to a session-based log file. If permissions/sandboxing are not tightly controlled and if untrusted parties can influence arguments or skill definitions, this combination can enable sensitive-data leakage and/or unintended command execution. Overall risk is driven by capability exposure and logging practices rather than confirmed malicious code.

Confidence: 60%Severity: 62%
Audit Metadata
Analyzed At
Mar 29, 2026, 08:53 AM
Package URL
pkg:socket/skills-sh/myuon%2Fagent-skills%2Fcreate-agent-skills%2F@6d3f86844c3c1553f08b48aaca97f59cba998d38