skill-generator
Warn
Audited by Socket on Sep 24, 2026
1 alert found:
SecuritySecurityspecs/scripting-integration.md
MEDIUMSecurityMEDIUM
specs/scripting-integration.md
No clear malicious behavior is present in this specification. The ExecuteScript example has a significant command-injection risk when scriptId or input values are untrusted, and insufficient scriptId/path validation. Use argument-array process execution and validate identifiers and resolved paths before invocation.
Confidence: 99%Severity: 72%
Audit Metadata