orchestrate
Warn
Audited by Socket on Sep 11, 2026
1 alert found:
AnomalyAnomalyscripts/unit.mjs
LOWAnomalyLOW
scripts/unit.mjs
No clear malware or supply-chain backdoor is present. The code is a repository/worktree and agent-session orchestration tool with expected external command and filesystem capabilities. The main security concern is intentional execution of the user-supplied --setup value via `sh -c`, plus execution of helper scripts selected through environment variables. These are high-impact capabilities if inputs or environment variables are attacker-controlled, but they do not by themselves demonstrate malicious intent.
Confidence: 96%Severity: 62%
Audit Metadata