skill-creator

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its stated purpose as a meta-tool for creating and benchmarking other skills, and the only evidenced external dependency is an official Anthropic CLI. However, it grants a wide operational footprint: command execution, background processes, browser/viewer generation, iterative rewriting of other skills, and possible processing of untrusted external content while retaining write/exec powers. That makes it a medium-risk orchestration skill rather than malware; the main concerns are autonomy breadth and indirect prompt-injection exposure, not credential theft or overt exfiltration.

Confidence: 82%Severity: 57%
Audit Metadata
Analyzed At
Apr 12, 2026, 02:45 AM
Package URL
pkg:socket/skills-sh/melumuccu%2Fai%2Fskill-creator%2F@c9dc8b0dd6270588ad39b533bb16d82cd42d737b