agent-creator
Warn
Audited by Socket on Apr 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's stated purpose is plausible, but it overclaims official Anthropic alignment while relying on a third-party, mutable `npx claude-flow@alpha` execution path and mismatched SDK package names. The main risk is supply-chain trust plus broad agent capabilities, not confirmed malware or direct exfiltration.
Confidence: 88%Severity: 62%
Audit Metadata