subrouter
Warn
Audited by Socket on Sep 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is broadly aligned with its stated purpose and shows unusual care around secret handling, but its actual footprint is high-impact. It persists long-lived credentials, forwards API traffic through a third-party gateway instead of official model vendors, and enables extensive authenticated management actions. No clear malware or covert exfiltration is present, but the scope and credential sensitivity make this a medium-risk skill.
Confidence: 90%Severity: 56%
Audit Metadata