creating-claude-agents

Warn

Audited by Socket on Feb 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected The fragment in Report 3 is the best among the three for guiding Claude Code agent creation and validation. It is benign, well-structured, and aligned with least-privilege tool usage. An improved final assessment would consolidate its guidance into a single, validated template and provide a clear, minimal-risk checklist to ensure correct frontmatter and content formatting. This reduces user confusion and enhances reproducibility for agent definitions. LLM verification: The markdown skill is not malware and contains no direct exfiltration behavior or hard-coded secrets. The primary security issue is guidance that can lead to dangerous runtime configurations (omitting allowed-tools / permissive Bash patterns) and an unsafe SQL interpolation example. This documentation can therefore enable risky deployment practices: require explicit allowed-tools, favor least privilege, fix the SQL example to show parameterization, and add tooling to enforce safe defaults.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 17, 2026, 11:33 PM
Package URL
pkg:socket/skills-sh/pr-pm%2Fprpm%2Fcreating-claude-agents%2F@1d34fe0986f7613c786bae38666eb05b36d58d42