create-partner
Warn
Audited by Socket on Apr 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core functionality matches the stated purpose, and there is no clear exfiltration or malware behavior, but the skill handles extremely sensitive third-party relationship data, grants Bash/Write access, and embeds unsanitized user input into shell commands including rm -rf. Combined with unpinned personal-repo installation and untrusted-content ingestion, this is a high security/privacy risk skill even though it is not confirmed malware.
Confidence: 84%Severity: 79%
Audit Metadata