orchestrate

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/unit.mjs

No clear malware or supply-chain backdoor is present. The code is a repository/worktree and agent-session orchestration tool with expected external command and filesystem capabilities. The main security concern is intentional execution of the user-supplied --setup value via `sh -c`, plus execution of helper scripts selected through environment variables. These are high-impact capabilities if inputs or environment variables are attacker-controlled, but they do not by themselves demonstrate malicious intent.

Confidence: 96%Severity: 62%
Audit Metadata
Analyzed At
Sep 11, 2026, 09:56 AM
Package URL
pkg:socket/skills-sh/hcaiano%2Fskills%2Forchestrate%2F@6f7fd024ca8007b5dba490531072b9508f695658b38d94cc47d09e1a7d626063
Security Audit — socket — orchestrate