using-agent-relay
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core messaging features align with the stated purpose, but the skill also enables agent spawning, webhooks, file upload, command invocation, and workspace key handling without install provenance or endpoint transparency. The footprint is broader than a simple coordination helper and creates meaningful transitive-trust and outbound-data risks.
Confidence: 77%Severity: 68%
Audit Metadata