mcp-dynamic-orchestrator
Warn
Audited by Socket on Jul 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's capabilities mostly match its stated MCP orchestration purpose, but it combines dynamic remote tool discovery with agent code execution and an insecure sandbox, and its example relies on an unpinned third-party npx bridge that may receive credentials. This is not confirmed malware, but it is higher-risk than a normal documentation or registry skill.
Confidence: 83%Severity: 72%
Audit Metadata