multi-ai-consultant

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No evidence of deliberate malicious code in this skill file. The primary security concern is operational: inadvertent leakage of sensitive repository data to external AI providers (via repo-aware scans and automatic consults) and supply-chain risk from installing third-party CLIs globally. Recommended remediations: require explicit interactive confirmation showing exact files/lines to be sent before any consultation (especially for automatic suggestions), implement safe-by-default .geminiignore templates (include .env*, *secret*, credentials), add optional preview/dry-run mode that lists files to be transmitted, avoid promoting unsafe flags (e.g., 'yolo'), recommend verifying package publisher signatures or using provider-distributed installers, and encrypt or restrict access to consultations.log (or allow opt-out). With those mitigations the security risk is reduced and the skill can be used safely.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:17 PM
Package URL
pkg:socket/skills-sh/secondsky%2Fclaude-skills%2Fmulti-ai-consultant%2F@41e8e4a040e0adde02f212ff555b8b63b4bedbca