tool-creator

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's main purpose is legitimate local tool creation, but it materially increases risk by turning user input into executable files, combining untrusted external research with write/exec capabilities, and invoking other skills transitively. There is no clear malware or credential-harvesting behavior, and no remote installer supply-chain pattern, but the scope and action surface are broader than a minimal tool creator.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
Apr 14, 2026, 06:14 AM
Package URL
pkg:socket/skills-sh/oimiragieo%2Fagent-studio%2Ftool-creator%2F@8509e911c9d73855a99309688b0b120c418b82ec