orchestrator
Warn
Audited by Socket on Mar 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose matches orchestration, but it grants an AI agent broad autonomous subprocess control, recursive review loops, and write/exec access over untrusted intermediate content. The largest concern is autonomy plus prompt-injection exposure; external CLI trust remains unclear because `oh-my-ag` provenance and data flows are not documented here.
Confidence: 81%Severity: 76%
Audit Metadata