agent-creator

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose is plausible, but it overclaims official Anthropic alignment while relying on a third-party, mutable `npx claude-flow@alpha` execution path and mismatched SDK package names. The main risk is supply-chain trust plus broad agent capabilities, not confirmed malware or direct exfiltration.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Apr 2, 2026, 07:21 AM
Package URL
pkg:socket/skills-sh/dnyoussef%2Fai-chrome-extension%2Fagent-creator%2F@0e52baab8abf1e44ef079aafa520d7ea37c8796c
Security Audit — socket — agent-creator