orchestrate

Warn

Audited by Socket on May 7, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/measurements.ts

No clear evidence of intentionally malicious/stealth behavior (no exfiltration, persistence, or credential theft visible). However, the module is security-critical because it ingests attacker-controlled repositories (unvalidated repoUrl/branch) and executes attacker-influenced shell text via `bash -c` (arbitrary command execution). Dynamic regex construction from untrusted configuration adds potential ReDoS/DoS risk. If any of repoUrl/branch/command/parser are not tightly controlled, this code materially elevates the likelihood of supply-chain compromise.

Confidence: 72%Severity: 82%
Audit Metadata
Analyzed At
May 7, 2026, 06:26 AM
Package URL
pkg:socket/skills-sh/cursor%2Fplugins%2Forchestrate%2F@1b7f1dd74b3e63406a16ae540c9cf01c88e605b0