create

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly aligned with plugin creation and shows no credential theft or covert exfiltration, but it is higher risk than a normal scaffolder because it can autonomously commit, push, trigger release automation, and invoke multiple other skills/tasks. Main concern is scope expansion and transitive trust, not confirmed malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 26, 2026, 03:33 PM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fcreate%2F@92bfa2a8c246516490744e780da2323091d5acb3