choom-delegation
Warn
Audited by Socket on Oct 9, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill’s purpose and capabilities are aligned, and there is no installer or binary trust issue. The main risk is opaque cross-agent delegation: tasks and possibly service settings are forwarded to unspecified remote Choom endpoints with their own prompts and tools, which expands trust and can expose data beyond the current agent boundary. Overall this is suspicious-but-not-malicious, with moderate security risk from undocumented data flows and transitive trust.
Confidence: 87%Severity: 58%
Audit Metadata