orchestrator
Warn
Audited by Socket on May 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s broad orchestration capabilities mostly fit its stated purpose, but trust is undermined by reliance on an unverified external 'ralph' CLI/scripts and by inaccurate claims about Anthropic Agent Teams being automatic/enabled by default. No clear credential theft or exfiltration is shown, but the combination of Bash, write access, recursive delegation, and unverifiable execution components makes this a high-risk orchestration skill rather than a benign narrowly-scoped helper.
Confidence: 84%Severity: 74%
Audit Metadata