using-agent-relay

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core messaging features align with the stated purpose, but the skill also enables agent spawning, webhooks, file upload, command invocation, and workspace key handling without install provenance or endpoint transparency. The footprint is broader than a simple coordination helper and creates meaningful transitive-trust and outbound-data risks.

Confidence: 77%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:44 PM
Package URL
pkg:socket/skills-sh/agentworkforce%2Frelay%2Fusing-agent-relay%2F@4bd6b3bfc4a4284c05e70e7abd2cbee3e91b36a2
Security Audit — socket — using-agent-relay