orchestrator

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose matches orchestration, but it enables high-autonomy execution through external CLI subagents with `--approval-mode=yolo` and feeds untrusted agent-generated content back into the control loop. No clear credential theft or exfiltration is shown, but execution trust and indirect prompt-injection risk are material.

Confidence: 83%Severity: 74%
Audit Metadata
Analyzed At
Mar 15, 2026, 10:46 PM
Package URL
pkg:socket/skills-sh/first-fluke%2Ffullstack-starter%2Forchestrator%2F@806d551847e61c32858a6617b4cd683109cd65d1