security-orchestrator

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent for a security orchestrator, but the skill delegates all meaningful security work and some high-impact actions to two unspecified skills with no verifiable provenance. No direct credential theft or external exfiltration is shown here, yet the transitive trust and autonomy footprint make it medium risk.

Confidence: 82%Severity: 63%
Audit Metadata
Analyzed At
Apr 18, 2026, 08:59 PM
Package URL
pkg:socket/skills-sh/fatih-developer%2Ffth-skills%2Fsecurity-orchestrator%2F@f4ec755daec100279694ac5d5d29a6e5e7a464bb