polyphony
Warn
Audited by Socket on May 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the orchestration concept is coherent, but the actual trust boundary is not. The skill forwards host credentials into an unspecified container image and relies on an unverified core CLI/image source, making its footprint disproportionate and high risk even though Docker/GitHub tooling themselves are legitimate.
Confidence: 90%Severity: 88%
Audit Metadata