ops-orchestrate
Warn
Audited by Socket on Oct 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's integrations target official services, but its actual footprint is much broader than a normal project helper. It reads local operational state and secrets, processes untrusted external content, spawns background agents, and can autonomously merge/admin-ship PRs across many repos; the eval-based quality gate adds command-execution risk. This looks like a high-risk orchestration skill rather than confirmed malware.
Confidence: 89%Severity: 78%
Audit Metadata