orchestrate-herdr
Warn
Audited by Socket on Jul 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose matches multi-agent GitHub orchestration, but the footprint is moderately risky because it autonomously launches a user-specified coding CLI across tabs, consumes untrusted GitHub issue content, and performs GitHub mutations. Data flows are mostly coherent and official, so this is not confirmed malicious, but the unconstrained CODING_CLI and companion-skill dependency make it a medium-risk orchestration skill.
Confidence: 81%Severity: 61%
Audit Metadata