skill-creator
Warn
Audited by Socket on Mar 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The presence of patterns that describe downloading and running external agents/tools (install/convert skills for the ecosystem) constitutes a potential remote-execution vector if the runtime ever executes these steps unsafely or with untrusted inputs. This aligns with a known risk surface where a skill could cause external binaries to be installed or run.
Confidence: 85%Severity: 70%
Audit Metadata