choom-delegation

Warn

Audited by Socket on Oct 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill’s purpose and capabilities are aligned, and there is no installer or binary trust issue. The main risk is opaque cross-agent delegation: tasks and possibly service settings are forwarded to unspecified remote Choom endpoints with their own prompts and tools, which expands trust and can expose data beyond the current agent boundary. Overall this is suspicious-but-not-malicious, with moderate security risk from undocumented data flows and transitive trust.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Oct 9, 2026, 08:42 AM
Package URL
pkg:socket/skills-sh/rotoslider%2Fchoom%2Fchoom-delegation%2F@f0f3fa5f5de166e779a2ae3aaa554a749b8f63cff2211d55257af39beaf47b2a