create-project-skills
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s core read/write behavior matches its stated purpose, and there is no evident credential theft or external exfiltration. The main concerns are transitive trust in an unseen /create-skill skill and elevated indirect prompt-injection risk from scanning untrusted repository content with parallel agents that can then write files.
Confidence: 85%Severity: 58%
Audit Metadata