mcp-dynamic-orchestrator

Warn

Audited by Socket on Jul 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's capabilities mostly match its stated MCP orchestration purpose, but it combines dynamic remote tool discovery with agent code execution and an insecure sandbox, and its example relies on an unpinned third-party npx bridge that may receive credentials. This is not confirmed malware, but it is higher-risk than a normal documentation or registry skill.

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
Jul 20, 2026, 09:50 PM
Package URL
pkg:socket/skills-sh/secondsky%2Fclaude-skills%2Fmcp-dynamic-orchestrator%2F@9e544026665a3346b16f9f5d55b39274af32ae6adc71499a63aa1014090253bd
Security Audit — socket — mcp-dynamic-orchestrator