auto-skill-creation

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is plausible, but the critical implementation is missing, so install trust and data flows cannot be verified. The snippet implies transitive capability expansion and possible third-party agent routing, but shows no clear credential harvesting or malicious exfiltration on its face. Risk is medium due to unverifiable behavior in unseen run.py rather than confirmed malware.

Confidence: 77%Severity: 56%
Audit Metadata
Analyzed At
Apr 1, 2026, 02:55 PM
Package URL
pkg:socket/skills-sh/cklxx%2Felephant.ai%2Fauto-skill-creation%2F@e9c99fd3749927659f8f0ebf98117f0a72180d88