advanced-skill-creator

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall, the fragment describes a sophisticated, multi-step skill-generation tool intended to standardize and automate the creation of OpenClaw/Moltbot/ClawDBot SKILL.md artifacts. The concept is coherent with its stated goal of enforcing best practices and official standards. However, the approach relies on external sources and automated tooling that could introduce supply-chain and prompt-injection risks if not properly sandboxed and validated. The footprint is not inherently malicious, but the combination of automated cross-skill analysis, heavy system-prompt integration, and potential execution of external tooling warrants a cautious,Suspicious designation. Proper safeguards (source pinning, sandboxed execution, explicit input validation, and restricted write scopes) are essential before deploying in a real environment.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 01:40 AM
Package URL
pkg:socket/skills-sh/ypyt1%2Fall-skills%2Fadvanced-skill-creator%2F@e877ac777e095b1cf557da707ffbf14380dd2b8e