create-skill

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is a benign scaffolding tool intended to generate and validate new Agent Skills per the official specification. There are no evident malicious capabilities, credential handling, or data exfiltration patterns. The most notable risk is the potential to pull in an external validator (skills-ref) as part of a normal workflow, which is an expected dependency for validation. Overall, the footprint is coherent with the stated purpose and remains proportionate to the task.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 05:44 AM
Package URL
pkg:socket/skills-sh/njzjz%2Fcreate-skill-agent-skill%2Fcreate-skill%2F@9a88156fa7879d1f8db72544e5099667dc902d3f
Security Audit — socket — create-skill