skill-creator

Warn

Audited by Socket on Mar 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The presence of patterns that describe downloading and running external agents/tools (install/convert skills for the ecosystem) constitutes a potential remote-execution vector if the runtime ever executes these steps unsafely or with untrusted inputs. This aligns with a known risk surface where a skill could cause external binaries to be installed or run.

Confidence: 85%Severity: 70%
Audit Metadata
Analyzed At
Mar 8, 2026, 03:31 PM
Package URL
pkg:socket/skills-sh/oimiragieo%2Fagent-studio%2Fskill-creator%2F@266ae705638a3612334c745987799c4778e9db3a