aider-delegate

Warn

Audited by Socket on Aug 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's behavior matches its stated purpose, but that purpose is high-trust orchestration of an external AI coding CLI. Main concerns are credential forwarding to Aider, arbitrary `--api-base` routing, and autonomous modification/tool execution in the local repo. Install provenance is mostly legitimate and same-project, so this looks more like a high-risk delegation workflow than confirmed malware.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Aug 16, 2026, 10:45 PM
Package URL
pkg:socket/skills-sh/amelnagdy%2Fdelegate-skills%2Faider-delegate%2F@2609b8b9eb6b10e095e178c456f111461fa62798e5a115e445e34eaa42570801
Security Audit — socket — aider-delegate