orchestrate
Warn
Audited by Socket on Sep 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's capabilities mostly match its stated purpose as a dev-loop orchestrator, and its external tools are official. The main risks are proportional but high-impact: autonomous code pushes/tracker actions, broad local repo/process control, and an optional Codex runner that explicitly disables approvals/sandbox and forwards repo context to an external service. No clear credential theft, covert exfiltration, or incompatible behavior was found.
Confidence: 89%Severity: 72%
Audit Metadata