orchestrator
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s core purpose is plausible, but it normalizes high-autonomy operation with all permissions, remote project mutations, and execution of an undocumented local script from ~/.config. Official GitHub tooling lowers supply-chain concern, yet the unsupervised real-world actions and transitive trust expansion make the overall skill high risk.
Confidence: 89%Severity: 82%
Audit Metadata