sub-agents

Fail

Audited by Socket on Apr 22, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill's core purpose is coherent, but it materially expands trust by routing tasks and workspace context into external AI CLIs, asks for elevated permissions, and allows arbitrary local agent definitions to choose the backend. Official provenance exists for most referenced CLIs, reducing malware certainty, but the delegation and mixed install trust make this a medium-high security risk skill.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 22, 2026, 03:27 PM
Package URL
pkg:socket/skills-sh/shinpr%2Fsub-agents-skills%2Fsub-agents%2F@19146bc28fbef96b22c30863b07f68deb5ef11ba