skill-creator

Fail

Audited by Socket on Feb 26, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
scripts/improve_description.py

This module implements intended functionality to improve skill descriptions by sending local skill content and evaluation results to an Anthropic Claude model and returning a rewritten description. It does not contain clear signs of malware or intentionally obfuscated malicious code. However, it poses a moderate privacy/supply-chain risk because it transmits raw local files (which may contain secrets or sensitive data) to an external service and can persist full transcripts to disk without redaction or strong safeguards. Treat this code as functional but requiring operational controls (sanitization, logging safeguards, error handling, and administrator awareness) before use in environments with sensitive data.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 26, 2026, 11:20 AM
Package URL
pkg:socket/skills-sh/tzwm%2Ffeishu-skill%2Fskill-creator%2F@5c26c1472b98de33a48074ba5d3efe3a727b8e37