aider-delegate
Warn
Audited by Socket on Aug 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's behavior matches its stated purpose, but that purpose is high-trust orchestration of an external AI coding CLI. Main concerns are credential forwarding to Aider, arbitrary `--api-base` routing, and autonomous modification/tool execution in the local repo. Install provenance is mostly legitimate and same-project, so this looks more like a high-risk delegation workflow than confirmed malware.
Confidence: 89%Severity: 72%
Audit Metadata