pal-mcp-server-multi-model-orchestration
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s capabilities largely match its stated multi-model orchestration purpose, and its credential use is proportionate for model APIs. Main concern is the unpinned uvx execution from a GitHub repo plus broad downstream trust in spawned external AI CLIs and provider routing; no clear evidence of credential theft, covert exfiltration, or fundamentally mismatched behavior was found.
Confidence: 82%Severity: 56%
Audit Metadata