project-orchestrator

Warn

Audited by Socket on Aug 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent and the named OpenSpec dependency appears legitimate, but this skill mainly acts as a high-privilege orchestrator that installs trust in multiple unspecified child skills and can trigger code/test/git workflows. No direct malware or exfiltration evidence is present, yet the transitive-skill model and incomplete provenance keep overall risk at medium.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Aug 14, 2026, 01:44 PM
Package URL
pkg:socket/skills-sh/hoangsoft90%2Fai_skills%2Fproject-orchestrator%2F@a07a6fc51924b9c4ff01e76931f528bcdcf831355d88acb65384a69b98f87411
Security Audit — socket — project-orchestrator