skill-generator

Warn

Audited by Socket on Sep 24, 2026

1 alert found:

Security
SecurityMEDIUM
specs/scripting-integration.md

No clear malicious behavior is present in this specification. The ExecuteScript example has a significant command-injection risk when scriptId or input values are untrusted, and insufficient scriptId/path validation. Use argument-array process execution and validate identifiers and resolved paths before invocation.

Confidence: 99%Severity: 72%
Audit Metadata
Analyzed At
Sep 24, 2026, 05:47 AM
Package URL
pkg:socket/skills-sh/catlog22%2Fclaude-code-workflow%2Fskill-generator%2F@3ded0594371923f1a4f8b4015e14250da6385ae88a8a5de04879ef30d988acb2