skill-creator

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/create.cjs

No direct evidence of malware or obfuscation is present in this wrapper, but it introduces a significant supply-chain/local-tampering risk by executing a local on-disk legacy artifact (create.legacy.cjs.bak) via runNodeScript. User-controlled CLI arguments influence execution in the fallback path, and the integrity/contents of the legacy artifact and the argument handling inside runNodeScript/actions are critical to overall risk. This should be reviewed and protected (e.g., artifact integrity checks, locked-down write permissions, and safe argument parsing/redaction in delegated code).

Confidence: 58%Severity: 60%
Audit Metadata
Analyzed At
Apr 26, 2026, 11:19 PM
Package URL
pkg:socket/skills-sh/oimiragieo%2Fagent-studio%2Fskill-creator%2F@f7d4fa862c795c45e3fa25a4471d64801e1624b1