autonomous-orchestrator

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's autonomous orchestration purpose matches its capabilities, but its footprint is unusually broad and high-impact. Continuous hands-off operation, blanket approval for user-owned repos, and processing of untrusted GitHub content while spawning action-taking agents create substantial autonomy and prompt-injection risk; the runtime `npx` dependency adds supply-chain risk.

Confidence: 87%Severity: 83%
Audit Metadata
Analyzed At
Apr 9, 2026, 07:49 AM
Package URL
pkg:socket/skills-sh/metyatech%2Fskill-autonomous-orchestrator%2Fautonomous-orchestrator%2F@52ac8a523189d2d85b244688f6fc0255166da4f4
Security Audit — socket — autonomous-orchestrator