skill-factory
Warn
Audited by Socket on May 9, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s core purpose broadly matches its capabilities, but it delegates major behavior to opaque local scripts and forwards full spec contents to external provider CLIs. The main risks are prompt-injection-through-spec, off-host data disclosure, and broad autonomous shell orchestration rather than clear malware or credential theft.
Confidence: 82%Severity: 68%
Audit Metadata