maestro

Warn

Audited by Socket on Jun 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's orchestration purpose matches its behavior, but its footprint is broad: Bash execution, direct in-context delegation to many other local skills, artifact-driven step growth, and auto-confirmed multi-step actions. The main risks are transitive trust and autonomous consequential actions, not confirmed malware or explicit exfiltration.

Confidence: 82%Severity: 68%
Audit Metadata
Analyzed At
Jun 24, 2026, 08:09 AM
Package URL
pkg:socket/skills-sh/catlog22%2Fmaestro-flow%2Fmaestro%2F@462132e6675a19b1f817ad7f85ceb43c2a156dbfafcdd67a13e88bf12ceeada3
Security Audit — socket — maestro