create-MamaSkill
Warn
Audited by Socket on Apr 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose mostly matches the capability to create a family-roleplay skill, and the local .claude/skills write path is coherent. The main issue is the unverifiable local script parse_wechat_history.py, which is asked to process highly sensitive private chat data without any provenance, source, or integrity information. No explicit network exfiltration is shown, so this is not confirmed malware, but it is a high-risk skill due to untrusted code execution on intimate personal data.
Confidence: 87%Severity: 82%
Audit Metadata