delegate-imagegen

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/delegate-cli.mjs

The fragment appears to be a legitimate multi-backend AI delegation wrapper. It contains no clear malicious code or covert exfiltration mechanism. It does create significant operational security risk by copying authentication material, importing MCP secrets/configuration, accepting filesystem paths, and launching agents with dangerous or full-access permissions. These risks should be treated as intentional framework capabilities and constrained with trusted requests, validated paths, least-privilege sandbox settings, trusted MCP configuration, and isolated credentials. No evidence of malware is present in the visible code.

Confidence: 92%Severity: 68%
Audit Metadata
Analyzed At
Sep 15, 2026, 12:40 AM
Package URL
pkg:socket/skills-sh/oubakiou%2Fdelegate-skills%2Fdelegate-imagegen%2F@e5e64b8ba254dd2d3554bcd87a882f0d66683f0ffbb5e98f43350e4a30e4a074
Security Audit — socket — delegate-imagegen