invoke-agent
Warn
Audited by Socket on Aug 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose and capabilities are mostly aligned, but its footprint is broader than a simple reference because it standardizes execution of multiple external AI CLIs with ambient auth and network access. No confirmed malware or hidden exfiltration appears, yet the multi-CLI trust chain, unpinned PATH dependence, and forwarding of user prompts to third-party agent software make it a medium-risk skill.
Confidence: 85%Severity: 61%
Audit Metadata