create-skill

Warn

Audited by Socket on May 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose is coherent and mostly documentation-oriented, but it instructs use of an unverifiable `samuel` CLI that is not supported by the official Agent Skills documentation or an established same-org release trail. There is no direct credential theft or exfiltration behavior, but the external tool dependency is disproportionate and creates a high supply-chain trust risk.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
May 13, 2026, 09:10 AM
Package URL
pkg:socket/skills-sh/ar4mirez%2Fsamuel%2Fcreate-skill%2F@9ac531369a106e5b0ef213d133e9f88205ff7e3d
Security Audit — socket — create-skill