delegate-imagegen
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalyscripts/delegate-cli.mjs
LOWAnomalyLOW
scripts/delegate-cli.mjs
The fragment appears to be a legitimate multi-backend AI delegation wrapper. It contains no clear malicious code or covert exfiltration mechanism. It does create significant operational security risk by copying authentication material, importing MCP secrets/configuration, accepting filesystem paths, and launching agents with dangerous or full-access permissions. These risks should be treated as intentional framework capabilities and constrained with trusted requests, validated paths, least-privilege sandbox settings, trusted MCP configuration, and isolated credentials. No evidence of malware is present in the visible code.
Confidence: 92%Severity: 68%
Audit Metadata