ops-orchestrate
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s capabilities largely match its orchestration purpose, and external endpoints appear official, so this is not confirmed malware. However, it grants an AI agent unusually broad autonomous authority across repos and issue systems, processes untrusted external content with write/exec permissions, uses eval on task metadata, and handles multiple high-value tokens; that makes it a high-risk orchestration skill even without clear credential theft or covert exfiltration.
Confidence: 90%Severity: 82%
Audit Metadata