skill-factory

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose broadly matches its capabilities, but it delegates major behavior to opaque local scripts and forwards full spec contents to external provider CLIs. The main risks are prompt-injection-through-spec, off-host data disclosure, and broad autonomous shell orchestration rather than clear malware or credential theft.

Confidence: 82%Severity: 68%
Audit Metadata
Analyzed At
May 9, 2026, 06:37 AM
Package URL
pkg:socket/skills-sh/nyldn%2Fclaude-octopus%2Fskill-factory%2F@e6d9fd6b46e8d9b9e37f22ce303748341093c237