omc

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill presents a coherent concept: a multi-agent orchestration framework for Claude Code with persistent loops and team-based execution. The described installation paths, optional external AI provider integrations, and notification endpoints are broadly consistent with the stated purpose. However, several risk signals emerge: exposure of credentials in configuration (Telegram/Discord tokens), use of global npm installs for external CLIs, and potential data exfiltration through notification endpoints. The combination of autonomous execution modes and third-party tool integrations raises security concerns that warrant careful credential handling, access control, and source verification. Overall, the footprint is suspicious to moderately high risk but not conclusively malicious. Treat as suspicious with mitigations: pin dependencies, avoid plaintext credentials in config, require explicit per-action user approvals for autonomous modes, and audit external CLI installations.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 01:21 PM
Package URL
pkg:socket/skills-sh/akillness%2Foh-my-skills%2Fomc%2F@dc6e62a1e523ba97ea99ff9538bf0a9a3203e870