multi-ai-consultant
Audited by Socket on Sep 15, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: the skill’s core purpose is coherent, and data appears intended to flow to official AI vendors, not a third-party proxy. However, the install instructions are inconsistent with current official package names, the skill forwards repo context and API keys to external CLIs/services, and it includes a --yolo verification pattern plus automatic-consult behavior that weakens user-control expectations. This is not confirmed malware, but it has medium security risk and should be corrected before trust.
This is documentation for troubleshooting a multi-AI consultation workflow. It contains no apparent malware or intentionally malicious code. However, several documented commands create credential-disclosure and operational-safety risks: plaintext API keys may be printed or persisted, API keys are placed in URLs, sensitive project files may be uploaded to external AI services, and Codex approval checks are disabled with --yolo. These are security weaknesses in the instructions rather than evidence of a malicious payload.