orchestrator

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core purpose is plausible, but it normalizes high-autonomy operation with all permissions, remote project mutations, and execution of an undocumented local script from ~/.config. Official GitHub tooling lowers supply-chain concern, yet the unsupervised real-world actions and transitive trust expansion make the overall skill high risk.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Mar 29, 2026, 02:54 PM
Package URL
pkg:socket/skills-sh/elihuvillaraus%2Fskills%2Forchestrator%2F@a73ec1f5e86a1c6d1b3efd31b4de76ae28e47275
Security Audit — socket — orchestrator