design-council-orchestration
Warn
Audited by Socket on May 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s stated purpose matches multi-agent orchestration, file reads, and decision-log writes, and it does not request secrets or show direct exfiltration. The main concerns are medium supply-chain risk from installing via a personal GitHub marketplace, explicit transitive plugin installation, and broad autonomous agent/action scope over local project content. This is not confirmed malware, but it is higher-risk than a normal documentation skill.
Confidence: 82%Severity: 64%
Audit Metadata