agency-orchestrator

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but its actual execution path relies on an unverified, unpinned npm package run via `npx -y`, and it advertises autonomous GitHub workflow actions. Main risk is supply-chain and downstream action authority rather than confirmed malware.

Confidence: 81%Severity: 79%
Audit Metadata
Analyzed At
Apr 1, 2026, 05:36 AM
Package URL
pkg:socket/skills-sh/KevinZai%2Fcc-commander%2Fagency-orchestrator%2F@77b2ec43f25e46e1e02d46ea92416dc8f54a9912
Security Audit — socket — agency-orchestrator