herdr-orchestration
Warn
Audited by Socket on Jul 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is coherent with its stated herdr orchestration purpose, but it normalizes unattended agent execution with disabled permission prompts (`--dangerously-skip-permissions`, `--yolo`) and depends on a third-party orchestration stack whose official install path uses curl|sh. I found no clear credential harvesting or exfiltration, so this is not confirmed malware, but it is a high-impact automation skill with meaningful security risk.
Confidence: 88%Severity: 72%
Audit Metadata