sub-agent

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose matches spawning agent CLIs, and official provenance is strong for Claude Code and Codex, but it deliberately enables high-autonomy delegated execution with reduced permission barriers and broad data exposure. The main risk is not hidden malware but a powerful meta-skill that forwards prompts, repository content, and implicit credentials/tool access to external agent CLIs, with weaker provenance clarity for OpenCode/Pi.

Confidence: 83%Severity: 74%
Audit Metadata
Analyzed At
Aug 1, 2026, 09:28 AM
Package URL
pkg:socket/skills-sh/opensquilla%2Fopensquilla%2Fsub-agent%2F@0f5e6d1de46976cc4df9103ca8a0f7b3ad0217f26eff6f941ab2b91aeee265b7
Security Audit — socket — sub-agent