model-routing
Warn
Audited by Socket on Sep 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the routing purpose is coherent, but the skill's trust model is weak because it requires multiple unverifiable local executables that automatically process prompts and likely handle API credentials. Data flows mostly match the stated routing function, yet the combination of a global hook, broad third-party prompt forwarding, and black-box local wrappers makes the overall footprint higher risk than a normal documentation-only skill.
Confidence: 82%Severity: 82%
Audit Metadata