draxarp

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s functionality is broadly consistent with a project-intelligence backend, but trust and data-flow integrity are weak: the Orbit/Draxarp command surface is not publicly verified from official docs, installer provenance is unspecified in-skill, and API tokens are forwarded to an arbitrary configured base_url rather than a pinned official service endpoint. This is not confirmed malware, but it is higher-risk than a normal documentation skill because it grants a preinstalled external CLI broad authenticated write/delete access to remote systems with limited provenance evidence.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 13, 2026, 10:22 PM
Package URL
pkg:socket/skills-sh/jorgemuza%2Forbit%2Fdraxarp%2F@02cdcbb3551ba68e4d9c3f1afdb44b39d7a9a433