Orchestration

Warn

Audited by Socket on Jun 19, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

Suspicious due to missing external install details, not because of confirmed malicious behavior. The stated blockchain orchestration purpose is plausible, but the real trust boundary is the unseen external installer, so provenance, permissions, credential handling, and data flows cannot be verified from the provided skill alone.

Confidence: 79%Severity: 58%
AnomalyLOW
catalog.json

No explicit malware is implemented in the provided fragment, but it introduces a significant supply-chain integrity risk by downloading unpinned remote orchestration instructions (SKILL.md) at install time and directing an agent/tool to consume them before scaffolding. Follow-on `yarn` build/deploy commands and third-party plugin installation broaden the trust boundary; review and add integrity verification (pinning/hashes/signatures) and inspect the fetched SKILL.md and referenced plugin code to rule out harmful instructions.

Confidence: 61%Severity: 60%
Audit Metadata
Analyzed At
Jun 19, 2026, 01:20 PM
Package URL
pkg:socket/skills-sh/BankrBot%2Fskills%2Forchestration%2F@1f578a8c9e0b68afaaf4f05a5ef38e2f8ab0d8cf
Security Audit — socket — Orchestration