gemini-use-claude-acp

Warn

Audited by Socket on May 12, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

Purpose and capabilities mostly align: this skill is clearly for delegating work to Claude. The main risk is not hidden malware but broad delegated authority: it auto-approves Claude tool use, enabling filesystem/shell actions in the target project without explicit approval per action. Runtime pnpm dlx execution adds moderate supply-chain risk, but there is no strong evidence of credential harvesting or covert exfiltration beyond the expected model delegation path.

Confidence: 100%Severity: 60%
SecurityMEDIUM
scripts/claude-delegate.mjs
Audit Metadata
Analyzed At
May 12, 2026, 07:09 AM
Package URL
pkg:socket/skills-sh/baphomet480%2Fclaude-skills%2Fgemini-use-claude-acp%2F@934be7fb850124d7a8fcecfcdc53595062cd25fc