workflow-orchestrator
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's core purpose is coherent, and it shows no direct credential theft, remote exfiltration, or untrusted installer use. However, automatic triggering of multiple unseen skills creates meaningful transitive-trust and autonomy risk that is disproportionate unless those downstream skills are verified and tightly scoped.
Confidence: 82%Severity: 61%
Audit Metadata