go

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The orchestration skill fulfills its intended function (parallel phased multi-agent execution) but introduces moderate-to-high supply-chain and data-exposure risk due to its requirements to embed full context into many spawned-agent prompts, to batch tool calls, and to delegate operations without least-privilege constraints or required human approvals. The module is not directly malicious, but its design enables credential leakage, transitive installation/execution, and autonomous external actions if spawn_agent grants agents broad capabilities. Recommended actions before deployment: enforce allowed_tools/connectors, add automatic secret redaction, require human gates for external-impacting phases, and prohibit transitive skill installation.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 28, 2026, 03:59 AM
Package URL
pkg:socket/skills-sh/anntnzrb%2Fagents%2Fgo%2F@01309a67973587ddd6f193aa7e9cde03c07ed09a