cross-agent-delegation

Warn

Audited by Socket on May 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s routing purpose is plausible, but it silently delegates code and context to multiple external AI tools, makes broad context capture mandatory, and performs autonomous third-party review without per-action approval. No direct credential theft is shown, but the hidden data flow and expanded tool footprint are disproportionate enough to warrant medium-high risk.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
May 6, 2026, 11:46 AM
Package URL
pkg:socket/skills-sh/alinaqi%2Fclaude-bootstrap%2Fcross-agent-delegation%2F@a2ba7b010b8cada4ed3bed5e6980d6755235473e