opencode-orchestrator-creator
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is mostly aligned with its stated local orchestration purpose and does not show credential theft or external exfiltration. Risk comes from enabling an autonomous curl-capable orchestrator that scans localhost, forwards untrusted multi-agent content, and references another skill, making it a medium-risk coordination skill rather than benign documentation.
Confidence: 87%Severity: 56%
Audit Metadata