orca-workflow
Warn
Audited by Socket on Jul 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core orchestration purpose is plausible, but the skill expands beyond normal workflow automation by sending persistent context to a third-party memory service, disabling TLS verification for those requests, and propagating skills across multiple agent runtimes. The external GitHub actions are purpose-aligned, but the AgentMemory data flow and curl -k usage materially raise risk.
Confidence: 89%Severity: 81%
Audit Metadata