orbit

Warn

Audited by Socket on Sep 18, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
reference/script-template-runner.md

The fragment appears to be a legitimate autonomous Git/LLM runner template, not an intentionally malicious implant. It has high operational privilege because it executes configurable shell commands and repository-local scripts, and it may disclose goal and diff content to configured LLM tools. These are material security risks if environment variables, repository files, or helper scripts are attacker-controlled, but no direct malware indicators or covert exfiltration behavior are present.

Confidence: 97%Severity: 62%
AnomalyLOW
reference/executor-engines.md

The fragment is executor-engine documentation with no direct evidence of malware or concealed malicious payloads. It documents powerful autonomous command execution and multiple permission-bypass modes, and its bash -c execution model would be dangerous if EXEC_CMD were derived from untrusted input. Treat EXEC_CMD as strictly trusted configuration, prefer wrappers and restricted tools, and avoid broad permission bypass where possible.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 18, 2026, 01:51 PM
Package URL
pkg:socket/skills-sh/simota%2Fagent-skills%2Forbit%2F@e4ff70361f91e41f00327975f107caffa47fc06a2975c4e226611541cd596e1b
Security Audit — socket — orbit