agents-consilium

Warn

Audited by Socket on Sep 15, 2026

3 alerts found:

SecurityAnomalyx2
SecurityMEDIUM
SKILL.md

Internally coherent skill for orchestrating external coding agents, not malware. The static findings are mostly documentation false positives, but the skill is still high risk operationally because it intentionally launches autonomous full-access delegates that can run commands, modify repositories, and send repository context to third-party model backends.

Confidence: 91%Severity: 74%
AnomalyLOW
scripts/lib/steer/adapters/codex.py

No clear malicious behavior or supply-chain payload is evident in the provided fragment. The main security concern is intentional but high-impact privilege configuration: the Codex subprocess receives full filesystem access and all approval requests are automatically accepted. This can allow tasks or model-generated actions to modify the host if the executable, prompt, session, or backend is compromised. Review the surrounding project and JsonRpcProcess implementation before deploying with untrusted tasks. The fragment is truncated at close(), limiting complete validation.

Confidence: 93%Severity: 68%
AnomalyLOW
README.md

This fragment is documentation for an external-agent delegation tool. It shows a potentially high-impact capability: delegate mode grants full access and may allow configured agents to modify repositories or perform other side effects. No direct malicious behavior, credential theft, obfuscated payload, or exfiltration is visible in the supplied portion. The implementation and backend security controls should be reviewed before treating the tool as safe, with particular attention to input handling, process isolation, configuration trust, and artifact contents.

Confidence: 93%Severity: 58%
Audit Metadata
Analyzed At
Sep 15, 2026, 04:11 AM
Package URL
pkg:socket/skills-sh/codealive-ai%2Fai-driven-development%2Fagents-consilium%2F@beaec423b15df639f6401b11a1c64d18523082620d8c2f2a6b4f45b64cd014f1
Security Audit — socket — agents-consilium