invoke-capability

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose matches delegated model invocation, but the skill routes user content through an opaque localhost bridge and hidden capability registry rather than directly documented provider APIs. That indirect data flow is not clearly malicious, yet it weakens data-flow transparency and trust. The instructions also encourage broad delegation and verbatim forwarding, including harsh content, which increases behavioral risk but does not by itself show credential theft or malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 09:42 AM
Package URL
pkg:socket/skills-sh/acking-you%2Fcodex-bridge%2Finvoke-capability%2F@4c21513d51dcf39cfd1f3291fbe677a56b788f14