provider-switch
Warn
Audited by Socket on Aug 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s main behavior is coherent with provider switching, and the documented provider endpoints appear official, but it persistently stores API keys in ~/.zshrc, forwards credentials to third-party providers/aggregators, and includes a hidden update workflow with web-research plus file-editing capabilities. This looks more like a high-risk configuration helper than confirmed malware.
Confidence: 85%Severity: 68%
Audit Metadata