sub-agent
Warn
Audited by Socket on Aug 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose matches spawning agent CLIs, and official provenance is strong for Claude Code and Codex, but it deliberately enables high-autonomy delegated execution with reduced permission barriers and broad data exposure. The main risk is not hidden malware but a powerful meta-skill that forwards prompts, repository content, and implicit credentials/tool access to external agent CLIs, with weaker provenance clarity for OpenCode/Pi.
Confidence: 83%Severity: 74%
Audit Metadata