orchestrate-review

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall, the fragment is a benign orchestration scaffold for multi-pass code review. It coordinates signals, passes, and findings without introducing external downloads, credential handling, or direct network activity. The primary risks are standard command construction (potential injection if inputs were untrusted) and the reliance on external Task agents, which expands the attack surface if those agents could be compromised. In a trusted environment with validated inputs and secured agent endpoints, the footprint aligns with its stated purpose of orchestrating code-review passes and aggregating findings. If inputs can be influenced by untrusted sources, treat as suspicious due to command string construction and prompt-based control flow paths.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 12:27 AM
Package URL
pkg:socket/skills-sh/avifenesh%2Fagentsys%2Forchestrate-review%2F@373d2e65b510f3af83b193677178844e3ddd9c0f