create-project-skills

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core read/write behavior matches its stated purpose, and there is no evident credential theft or external exfiltration. The main concerns are transitive trust in an unseen /create-skill skill and elevated indirect prompt-injection risk from scanning untrusted repository content with parallel agents that can then write files.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 05:25 PM
Package URL
pkg:socket/skills-sh/tobihagemann%2Fturbo%2Fcreate-project-skills%2F@03972d119358748f36b5eaabc1eb7b7bfed072de