create-lang-plugin

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches the examples, but the skill is a generic execution bridge that normalizes sending agent-controlled code into arbitrary external CLIs/runtimes with no provenance requirements. There is no direct credential theft or outbound exfiltration in the text, yet the dependency model is too open-ended to treat as benign.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
May 17, 2026, 10:33 AM
Package URL
pkg:socket/skills-sh/AnEntrypoint%2Fgm-skill%2Fcreate-lang-plugin%2F@94699dbb126f6b6ddaa4dc07f7cc27cfe122f881
Security Audit — socket — create-lang-plugin