orca-workflow

Warn

Audited by Socket on Jun 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent as an orchestration workflow, but its footprint is broader than a simple proposal tool: it can dispatch tasks to other agents and automatically sync modified skill files to a remote GitHub repo over SSH. No clear malware or hidden exfiltration is present, yet the outbound repo sync and multi-agent action surface make this a medium-risk skill that should be used only with explicit user oversight.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Jun 18, 2026, 03:44 AM
Package URL
pkg:socket/skills-sh/rheinmir%2Fsetup%2Forca-workflow%2F@0ee9cded2783ef16294893b85ae451465d0a8de6
Security Audit — socket — orca-workflow