skill-navigator

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Skill Navigator appears to be a framework-centric orchestration guide designed to route tasks to domain-specific skills using orchestrator-first loading and progressive disclosure. Its security footprint, as described, is benign: no external downloads, no credential handling, and no evident data exfiltration paths. Data flows are internal and plan-based, aligning with the stated purpose of managing token budgets and modular loading. Given the absence of credential usage, unverifiable binaries, or external network interactions in the described content, the overall risk posture is low to moderate (benign), with mild concern around potential misconfigurations in real deployments where orchestrator/worker interactions could broaden data access if not properly constrained. Reserve heightened scrutiny if any downstream workers introduce untrusted code, external dependencies, or credential forwarding in actual implementations.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:35 AM
Package URL
pkg:socket/skills-sh/databricks-solutions%2Fvibe-coding-workshop-template%2Fskill-navigator%2F@bf623e85e33385dae94b445e2abac01f0e0b3b66