multi-agent-client-onboarding

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose is coherent and the cited Agent SDK provenance appears official, so this is not malware-like or deceptive. However, it combines WebSearch and arbitrary external/client content with Bash, Write, and parallel Agent execution, creating medium risk from indirect prompt injection and over-broad autonomous action for a consulting-report skill.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
Apr 10, 2026, 05:28 PM
Package URL
pkg:socket/skills-sh/onewave-ai%2Fclaude-skills%2Fmulti-agent-client-onboarding%2F@c01ddc98fdeeff1872965511e7d905c6dce2b04a