multi-llm-consult
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's capabilities broadly match its purpose, and there is no obvious malicious installer or overt exfiltration endpoint. However, it is designed to transmit user prompts and optional local files to external LLMs using multiple stored API keys through an unseen bundled script, while only asserting rather than demonstrating sanitization and direct-to-official data flows. That makes the footprint coherent but only partially verifiable, with moderate data-leak and credential-handling risk.
Confidence: 82%Severity: 56%
Audit Metadata