pal-mcp-server-multi-model-orchestration
Warn
Audited by Socket on May 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s capabilities mostly match its purpose, and the install source appears to be the same org as the upstream project, so this is not confirmed malware. However, it meaningfully expands the agent’s trust boundary through unpinned GitHub execution, multiple API-key handling, and external CLI subagents that can process project data and act on it.
Confidence: 86%Severity: 66%
Audit Metadata