delegation

Warn

Audited by Socket on May 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its stated delegation purpose and shows no obvious credential theft or exfiltration, but it grants an AI agent substantial autonomous control over code execution, branch manipulation, dependency installation, and transitive skill invocation. The biggest risks are autonomous real-world code changes and npm-based supply-chain exposure, not confirmed malware.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
May 6, 2026, 04:05 AM
Package URL
pkg:socket/skills-sh/lvlup-sw%2Fexarchos%2Fdelegation%2F@b3286122475b569c2a6f1ad3ef103005f01183c0
Security Audit — socket — delegation