external-model-delegation

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, and the cited Codex/Kimi tooling appears to have official distribution paths, but the pattern automatically routes every user prompt through local wrapper scripts and potentially to third-party model providers without explicit per-prompt approval. That makes the scope moderately risky: prompt data and API-backed delegation are central to the design, yet the unspecified ~/bin scripts and automatic hook behavior increase trust and data-leak exposure beyond a simple documentation skill.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Sep 16, 2026, 01:46 PM
Package URL
pkg:socket/skills-sh/alinaqi%2Fmaggy%2Fexternal-model-delegation%2F@1d9f8c4820fb48a4beee8422115b2329598c5a1c7f6e20c34fe44ab8046e8b7f
Security Audit — socket — external-model-delegation