create-agent-adapter
Warn
Audited by Socket on Apr 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is a legitimate-seeming developer guide, but its actual footprint is inherently high-trust because it teaches agents to spawn arbitrary local CLIs or call arbitrary HTTP endpoints and to pass API tokens/secrets into those runtimes. The capabilities mostly match the stated purpose, so this is not confirmed malicious, but the broad adapter surface and credential forwarding make it a medium-risk skill.
Confidence: 86%Severity: 61%
Audit Metadata