auto-skill-creation
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The stated purpose is plausible, but the critical implementation is missing, so install trust and data flows cannot be verified. The snippet implies transitive capability expansion and possible third-party agent routing, but shows no clear credential harvesting or malicious exfiltration on its face. Risk is medium due to unverifiable behavior in unseen run.py rather than confirmed malware.
Confidence: 77%Severity: 56%
Audit Metadata