spec-orchestrate

Warn

Audited by Socket on Aug 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core orchestration purpose is coherent, but the skill has a high-impact footprint: unattended Issue-to-PR automation, transitive dependence on other worker skills/delegation backends, and processing of untrusted Issue content that can drive code changes and PR creation. No confirmed credential theft or overt malware is shown, but overall risk is medium-high due to autonomy and prompt-injection exposure.

Confidence: 86%Severity: 76%
Audit Metadata
Analyzed At
Aug 17, 2026, 04:53 PM
Package URL
pkg:socket/skills-sh/anyoneanderson%2Fagent-skills%2Fspec-orchestrate%2F@31a6764a578bfe45d889da644ba06b25572041682aedebdae607cc004ded7ab1
Security Audit — socket — spec-orchestrate