create-verification-skill
Warn
Audited by Socket on Sep 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s core behavior is coherent for generating a verification harness, but it expands trust by installing/linking another skill and asks the agent to execute repo-derived commands after interpreting untrusted repository content. No clear credential theft or exfiltration path is present, so this is not malware, but the transitive trust-chain and indirect prompt-injection exposure make it medium risk.
Confidence: 82%Severity: 57%
Audit Metadata