tool-creator
Warn
Audited by Socket on Apr 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's main purpose is legitimate local tool creation, but it materially increases risk by turning user input into executable files, combining untrusted external research with write/exec capabilities, and invoking other skills transitively. There is no clear malware or credential-harvesting behavior, and no remote installer supply-chain pattern, but the scope and action surface are broader than a minimal tool creator.
Confidence: 89%Severity: 68%
Audit Metadata