orchestrate

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the visible stub is small and its stated purpose is plausible, but almost all real behavior is delegated to an unseen local workflow. Gemini CLI likely comes from an official source, yet the hidden workflow could materially expand command, credential, or network scope; MCP memory provenance is also unspecified. Risk is driven more by opacity and delegated execution than by confirmed malicious behavior.

Confidence: 80%Severity: 56%
Audit Metadata
Analyzed At
Apr 10, 2026, 09:41 AM
Package URL
pkg:socket/skills-sh/first-fluke%2Ffullstack-starter%2Forchestrate%2F@22b37bbac3b734693448ac750f4b87ddb4c938e3
Security Audit — socket — orchestrate