skill-builder

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: overall coherent as a skill scaffolder, but it carries medium risk from transitive skill/tool trust and from ingesting untrusted external SKILL.md content while writing files and invoking converters/auditors. No clear credential theft, exfiltration, or malicious mismatch with stated purpose is present.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 10:59 AM
Package URL
pkg:socket/skills-sh/boshu2%2Fagentops%2Fskill-builder%2F@45ef1291b19940f0b7b57ba804dc4fa6bdbdc1e2
Security Audit — socket — skill-builder