herdr-orchestration

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated purpose as a herdr-based orchestration guide, and the referenced herdr project appears official. However, it is built around launching unattended worker TUIs with approval-bypass flags, allowing autonomous code changes and command execution at scale. This is coherent for orchestration, but still high-risk because it weakens safety controls rather than merely documenting them.

Confidence: 92%Severity: 74%
Audit Metadata
Analyzed At
Sep 12, 2026, 07:35 PM
Package URL
pkg:socket/skills-sh/pedronauck%2Fskills%2Fherdr-orchestration%2F@f4b0c0445746bb2680491d2106e04d10a83d93cf4f832ae1d700986d5efea0f7
Security Audit — socket — herdr-orchestration