self-healing-orchestrator

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The manifest defines a powerful orchestration skill capable of reading error reports and performing high-impact remediation actions including generating and deploying hotfixes. The design as presented lacks essential security controls: explicit credential sourcing and scoping, RBAC/namespace constraints, enforced human approval semantics, artifact provenance (code-signing), audit logging, output redaction, and safe deployment practices (canaries, automated rollback). These gaps create realistic risks of credential exposure, unauthorized changes, and supply-chain injection. The specification is not evidence of malware, but without strong governance and technical controls the implementation would be high-risk for production use and could be abused or compromised to perform malicious activity.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 4, 2026, 10:06 PM
Package URL
pkg:socket/skills-sh/famaoai-creator%2Fgemini-skills%2Fself-healing-orchestrator%2F@b028106edc4b0eb02a4b91eb193735921f8de56c