orchestrator

Warn

Audited by Socket on May 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s broad orchestration capabilities mostly fit its stated purpose, but trust is undermined by reliance on an unverified external 'ralph' CLI/scripts and by inaccurate claims about Anthropic Agent Teams being automatic/enabled by default. No clear credential theft or exfiltration is shown, but the combination of Bash, write access, recursive delegation, and unverifiable execution components makes this a high-risk orchestration skill rather than a benign narrowly-scoped helper.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
May 3, 2026, 11:08 AM
Package URL
pkg:socket/skills-sh/alfredolopez80%2Fmulti-agent-ralph-loop%2Forchestrator%2F@a0166d68d65b70d08eee145000d3ed076cf37b6f
Security Audit — socket — orchestrator