skill-creator

Fail

Audited by Socket on Jun 15, 2026

2 alerts found:

AnomalyObfuscated File
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core behavior is largely consistent with a skill-authoring tool, but it expands trust by invoking other skills and suggests exec-based dependency installation with unpinned packages. No clear credential harvesting or exfiltration is shown, so this is not confirmed malware; the main concerns are supply-chain and transitive-trust risk.

Confidence: 100%Severity: 60%
Obfuscated FileHIGH
scripts/improve_description.py

This module implements intended functionality to improve skill descriptions by sending local skill content and evaluation results to an Anthropic Claude model and returning a rewritten description. It does not contain clear signs of malware or intentionally obfuscated malicious code. However, it poses a moderate privacy/supply-chain risk because it transmits raw local files (which may contain secrets or sensitive data) to an external service and can persist full transcripts to disk without redaction or strong safeguards. Treat this code as functional but requiring operational controls (sanitization, logging safeguards, error handling, and administrator awareness) before use in environments with sensitive data.

Confidence: 90%
Audit Metadata
Analyzed At
Jun 15, 2026, 12:07 PM
Package URL
pkg:socket/skills-sh/nextlevelbuilder%2Fgoclaw%2Fskill-creator%2F@28d805fe0233d5dadb0eedb7fc0fb781bf51995373196d6c9580e337fe7a7cb4
Security Audit — socket — skill-creator