gemini-use-claude-acp
Warn
Audited by Socket on May 12, 2026
2 alerts found:
AnomalySecurityAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
Purpose and capabilities mostly align: this skill is clearly for delegating work to Claude. The main risk is not hidden malware but broad delegated authority: it auto-approves Claude tool use, enabling filesystem/shell actions in the target project without explicit approval per action. Runtime pnpm dlx execution adds moderate supply-chain risk, but there is no strong evidence of credential harvesting or covert exfiltration beyond the expected model delegation path.
Confidence: 100%Severity: 60%
Securityscripts/claude-delegate.mjs
MEDIUMSecurityMEDIUM
scripts/claude-delegate.mjs
Audit Metadata