text2agent

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core purpose is plausible, but its footprint is broad: it reads external skill content, writes executable agent code, dynamically registers agents, and auto-installs dependencies through unpinned runtime package execution. The official Playwright MCP reference lowers the chance of outright malware, but the combination of autonomous system changes, prompt reuse from untrusted SKILL files, and dynamic installs makes this a high security-risk meta-skill.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Mar 28, 2026, 05:59 AM
Package URL
pkg:socket/skills-sh/inclusionAI%2FAWorld%2Ftext2agent%2F@85618391e5ed563f6b8d1cd16e1043b5a0ff925b