skill-creator

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill-creator content is a benign, self-referential framework outlining best practices for designing, organizing, and packaging AI agent skills. There are no concrete instructions to download, execute unknown binaries, exfiltrate data, or access sensitive credentials. While it mentions external tooling (init_skill.py, package_skill.py) as part of a typical workflow, it does not embed or distribute executable payloads or credential handling within this fragment. Overall, the footprint is coherent with a documentation/education purpose and poses minimal security risk in this isolated assessment.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/smallnest%2Fgoclaw%2Fskill-creator%2F@8b6c116a07ae99ccf3ccc39f63d6a396130b0fe4