zcode-delegate

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, and credential/network flows mostly target official Z.AI infrastructure, but the trust boundary is weak because the actual relay runtime is missing, the publisher is a community account, and the executed CLI path can be redirected to any local binary. This is not confirmed malware, but it is a high-risk delegation skill with meaningful supply-chain and credential-forwarding exposure.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Sep 2, 2026, 03:49 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fagentic-awesome-skills%2Fzcode-delegate%2F@5b914206298bcf86de3ecd0838f135deef9fdbd32e4efe7df308ded304a72ca8
Security Audit — socket — zcode-delegate