agent-orchestration

Warn

Audited by Socket on Aug 26, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose matches orchestration setup, and the visible install command uses an official npm CLI, but the skill’s main action is transitive installation of another remote skill from a third-party GitHub repo plus host init scripts whose contents are not shown. That makes the footprint coherent yet moderately risky from a supply-chain and inherited-permissions perspective rather than overtly malicious.

Confidence: 88%Severity: 58%
AnomalyLOW
assets/claude/skills/cursor-worker-implement/SKILL.md

SUSPICIOUS. The skill’s core behavior is mostly aligned with its stated purpose—delegating bulk implementation to the official Cursor CLI—but it expands trust to a black-box external agent that can autonomously edit files and run shell commands with `--force`. The main concerns are supply-chain hygiene of the preinstalled CLI, prompt/workspace-to-execution risk, and transitive trust to another skill, not confirmed malware or credential theft.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:14 AM
Package URL
pkg:socket/skills-sh/fixmyberlin%2Ffixmyskills%2Fagent-orchestration%2F@4712f87394c4a459f317f4ac58f67f0ff98c9b8a9dd9b810a556d2fdd1bc6340
Security Audit — socket — agent-orchestration