skill-creator

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Credential file access detected All findings: [HIGH] data_exfiltration: Credential file access detected (DE002) [AITech 8.2.3] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] The fragment is a benign, coherent documentation/specification for creating Agent Skills (SKILL.md). It aligns with its described purpose, has no evidence of malicious behavior, and does not request sensitive credentials or perform any data transmission. Overall security risk is low, with minor caution about ensuring future implementations derived from this guide follow the same security-conscious patterns.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:31 PM
Package URL
pkg:socket/skills-sh/jkappers%2Fagent-skills%2Fskill-creator%2F@576e20ad4dd86b6706e9226829f4f8a5dcbcf6a4