external-model-delegation
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose and capabilities mostly align, and the cited Codex/Kimi tooling appears to have official distribution paths, but the pattern automatically routes every user prompt through local wrapper scripts and potentially to third-party model providers without explicit per-prompt approval. That makes the scope moderately risky: prompt data and API-backed delegation are central to the design, yet the unspecified ~/bin scripts and automatic hook behavior increase trust and data-leak exposure beyond a simple documentation skill.
Confidence: 87%Severity: 58%
Audit Metadata