delegate-task

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is broad delegation, but it routes tasks and local skill content into an external autonomous ecosystem that can auto-import third-party skills and upload evolved ones. The main risks are transitive skill installation, prompt injection from untrusted remote skills/content, and open-ended autonomous actions through an external worker.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
Mar 30, 2026, 06:43 AM
Package URL
pkg:socket/skills-sh/HKUDS%2FOpenSpace%2Fdelegate-task%2F@a293e9fb9cb7ec8902d8fe1df810f9cea400de1b