lifecyclemodel-recursive-orchestrator

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall suspicious rather than malicious. The capability set is coherent for a local orchestration skill and the documented data flow is local-only, but the core dependency on an unverifiable tiangong CLI creates a high supply-chain trust concern. No evidence here of credential harvesting, covert exfiltration, remote posting, or hidden execution.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
May 17, 2026, 06:58 AM
Package URL
pkg:socket/skills-sh/tiangong-lca%2Fskills%2Flifecyclemodel-recursive-orchestrator%2F@cd4724822d7c89d1ba2e6b1001145c5d5589f32d
Security Audit — socket — lifecyclemodel-recursive-orchestrator