design-council-orchestration

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose matches multi-agent orchestration, file reads, and decision-log writes, and it does not request secrets or show direct exfiltration. The main concerns are medium supply-chain risk from installing via a personal GitHub marketplace, explicit transitive plugin installation, and broad autonomous agent/action scope over local project content. This is not confirmed malware, but it is higher-risk than a normal documentation skill.

Confidence: 82%Severity: 64%
Audit Metadata
Analyzed At
May 17, 2026, 07:30 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fdesign-skills%2Fdesign-council-orchestration%2F@1a98b5545bd79118989444e9057d07457a9a5270