zcode-delegate

Warn

Audited by Socket on Aug 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: internally coherent for a ZCode delegation skill, with official same-org endpoints and no obvious credential-harvesting route, but it delegates code changes to an external proprietary CLI that can receive API keys and modify the repo in headless write mode. Main risk is trusted execution of a black-box implementer, not overt malicious behavior.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Aug 20, 2026, 09:47 AM
Package URL
pkg:socket/skills-sh/amelnagdy%2Fdelegate-skills%2Fzcode-delegate%2F@6043478d14042fbbf72a56c6c44853a1b9bd318eed7b76f9ab6d76ead31e8272
Security Audit — socket — zcode-delegate