multi-ai-consultant

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, and data appears intended to flow to official AI vendors, not a third-party proxy. However, the install instructions are inconsistent with current official package names, the skill forwards repo context and API keys to external CLIs/services, and it includes a --yolo verification pattern plus automatic-consult behavior that weakens user-control expectations. This is not confirmed malware, but it has medium security risk and should be corrected before trust.

Confidence: 88%Severity: 53%
AnomalyLOW
references/troubleshooting.md

This is documentation for troubleshooting a multi-AI consultation workflow. It contains no apparent malware or intentionally malicious code. However, several documented commands create credential-disclosure and operational-safety risks: plaintext API keys may be printed or persisted, API keys are placed in URLs, sensitive project files may be uploaded to external AI services, and Codex approval checks are disabled with --yolo. These are security weaknesses in the instructions rather than evidence of a malicious payload.

Confidence: 98%Severity: 56%
Audit Metadata
Analyzed At
Sep 15, 2026, 12:04 AM
Package URL
pkg:socket/skills-sh/secondsky%2Fclaude-skills%2Fmulti-ai-consultant%2F@ec6ff90b177b1cb2aec67e5f92ee76cb91fc61725cea0ced18c563b213a67f8a
Security Audit — socket — multi-ai-consultant