orchestrator-subsystems

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core issue is not malware-level exfiltration but hidden autonomous behavior. The skill normalizes silent background recording, continuous learning, auto-fixes, and possible Git-impacting actions after every task without explicit approval. Its local-only data flow limits evidence of outright credential theft, but the concealment directives and disproportionate autonomy make the skill unsafe and misaligned with a normal orchestration reference.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Apr 23, 2026, 02:36 PM
Package URL
pkg:socket/skills-sh/bejranonda%2FLLM-Autonomous-Agent-Plugin-for-Claude%2Forchestrator-subsystems%2F@441577e3625c11ffa340ea20ca56a0741d5a6c6b