zai-orchestrator
Warn
Audited by Socket on Sep 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s stated purpose matches its orchestration instructions, and there is no direct credential theft, exfiltration, or hidden execution. The main risk is transitive trust: it tells the agent/user to install multiple other skills from a third-party GitHub repository, so meaningful behavior is delegated to external skills that are not independently reviewed here.
Confidence: 90%Severity: 52%
Audit Metadata