create-lang-plugin
Warn
Audited by Socket on May 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose matches the examples, but the skill is a generic execution bridge that normalizes sending agent-controlled code into arbitrary external CLIs/runtimes with no provenance requirements. There is no direct credential theft or outbound exfiltration in the text, yet the dependency model is too open-ended to treat as benign.
Confidence: 87%Severity: 72%
Audit Metadata