command-creator
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose matches creating slash commands, but the skill normalizes OpenCode pre-execution shell syntax that runs before approval and includes an example (`gh issue list --search "$ARGUMENTS"`) that embeds user-controlled input into a shell command. No external installer, malware payload, credential theft, or off-platform exfiltration is present, so this is not confirmed malicious; the main risk is unsafe command-template generation with load-time execution.
Confidence: 91%Severity: 76%
Audit Metadata