ziw-orchestrate

Warn

Audited by Socket on Jun 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities largely match its stated orchestration purpose, and I found no direct malware signals, hidden exfiltration, or installer abuse in the skill itself. However, it grants a self-driving agent broad workflow authority, can trigger real repository and tracker actions, processes untrusted external content, and depends on other skills/agents, making it a medium-high operational security risk despite being internally coherent.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 15, 2026, 04:11 PM
Package URL
pkg:socket/skills-sh/zaks-io%2Fskills%2Fziw-orchestrate%2F@bfe4e4976dce2d693c5881528e46b1caa2db41cb0e7e374b6ae4beb4e3affc95
Security Audit — socket — ziw-orchestrate