ah-a2a

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally consistent with its stated purpose and uses an apparently official CLI/source chain, so it is not outright malicious. However, its core function is to route user tasks, optional local files, and authenticated actions to remote third-party agents on an open network, with endpoint override and multi-agent orchestration increasing exposure. Risk is driven more by external delegation and data-sharing than by deceptive install behavior.

Confidence: 85%Severity: 64%
Audit Metadata
Analyzed At
May 18, 2026, 04:09 AM
Package URL
pkg:socket/skills-sh/annals-ai%2Fah-cli%2Fah-a2a%2F@707fccbacad85459acc95cd2c84558c96214c8a9