zcode-delegate
Warn
Audited by Socket on Aug 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: internally coherent for a ZCode delegation skill, with official same-org endpoints and no obvious credential-harvesting route, but it delegates code changes to an external proprietary CLI that can receive API keys and modify the repo in headless write mode. Main risk is trusted execution of a black-box implementer, not overt malicious behavior.
Confidence: 84%Severity: 56%
Audit Metadata