cli-skill-creator
Warn
Audited by Socket on Apr 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core purpose is legitimate and most capabilities fit CLI documentation, but the skill expands trust by cloning arbitrary repos, consuming untrusted online content, and delegating to another skill. No credential harvesting or clear exfiltration appears, so this is not malicious; the main risks are transitive trust, supply chain exposure, and indirect prompt injection during research.
Confidence: 85%Severity: 56%
Audit Metadata