orchestrate

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the visible skill is only a thin wrapper around an unseen local workflow, so its true capabilities, data flows, and approval boundaries cannot be verified. The named Gemini CLI looks official, which lowers supply-chain concern, but the hidden orchestration logic and multi-agent execution make the overall footprint broader and less reviewable than the snippet alone suggests.

Confidence: 80%Severity: 56%
Audit Metadata
Analyzed At
Mar 28, 2026, 03:26 AM
Package URL
pkg:socket/skills-sh/first-fluke%2Foh-my-ag%2Forchestrate%2F@0d55bd40c93a073d69b97aa1708ef0f1c1c606f1