parallel-execution

Fail

Audited by Socket on Mar 5, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The document is an operational guide for parallelizing independent subagent tasks. It does not contain explicit malicious code, obfuscated payloads, hardcoded credentials, or network endpoints. However, it increases supply-chain and operational risk by (1) broadcasting local context and task definitions into multiple subagent prompts (prompt-injection and data-leak potential), (2) enabling multiple autonomous subagent actions in a single message (amplifies impact of compromise or misconfiguration), and (3) invoking a local shell orchestration script whose behavior is unknown. Treat this pattern as useful but risky: require provenance checks for preloaded files, limit which files are embedded in prompts, restrict subagent privileges (especially network and execution rights), and add human or automated policy gates before batch execution.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 5, 2026, 12:51 PM
Package URL
pkg:socket/skills-sh/darrenhinde%2FOpenAgentsControl%2Fparallel-execution%2F@0eb00a322a7b3bdf3703d0b2b88aac9984240b4c