zai-orchestrator

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align, and there is no clear credential harvesting or exfiltration path. The main concern is transitive installation of multiple dependent skills from a third-party repo plus prompt-injection exposure from untrusted web/repo content under broad tool scopes.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 28, 2026, 11:45 PM
Package URL
pkg:socket/skills-sh/tianxiao1430-jpg%2Fzai-skills%2Fzai-orchestrator%2F@5cebe03082f64a9fa413b19c08cf6aa572e46b28