workflow-orchestrator

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core purpose is coherent, and it shows no direct credential theft, remote exfiltration, or untrusted installer use. However, automatic triggering of multiple unseen skills creates meaningful transitive-trust and autonomy risk that is disproportionate unless those downstream skills are verified and tightly scoped.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/charon-fan%2Fagent-playbook%2Fworkflow-orchestrator%2F@a62e6c3846dcb2eda46a95f0f7e8035cb61db100