agency-orchestrator
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent, but its actual execution path relies on an unverified, unpinned npm package run via `npx -y`, and it advertises autonomous GitHub workflow actions. Main risk is supply-chain and downstream action authority rather than confirmed malware.
Confidence: 81%Severity: 79%
Audit Metadata