oma-orchestrator

Warn

Audited by Socket on May 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s orchestration behavior matches its stated purpose, but its footprint is high risk. The main concerns are autonomous parallel subagent execution, processing of untrusted workspace/review content with write/exec access, and reliance on a third-party fallback CLI whose official installation includes unsafe raw GitHub installer patterns. This is not confirmed malware, but it is a high-risk automation skill.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
May 16, 2026, 06:56 AM
Package URL
pkg:socket/skills-sh/first-fluke%2Foh-my-agent%2Foma-orchestrator%2F@3a3a2a259001fddb78157379befc3fcddf0d203e
Security Audit — socket — oma-orchestrator