parallel-swarm-implementation

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s broad orchestration behavior mostly matches its stated meta-skill purpose, and the main external tool (`claude-flow`) appears to be a real same-project npm/GitHub dependency rather than an obvious fake installer. However, it materially expands trust by dynamically invoking other skills/agents, uses an unpinned alpha-channel CLI, forwards project data into external memory/hook tooling, and enables highly autonomous execution loops. This is better classified as a high-risk orchestration skill than confirmed malware.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Apr 2, 2026, 07:18 AM
Package URL
pkg:socket/skills-sh/dnyoussef%2Fai-chrome-extension%2Fparallel-swarm-implementation%2F@497ec20e1a9469e351451667e5feb57b1caaae36
Security Audit — socket — parallel-swarm-implementation