orchestrator

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose matches orchestration, but it grants an AI agent broad autonomous subprocess control, recursive review loops, and write/exec access over untrusted intermediate content. The largest concern is autonomy plus prompt-injection exposure; external CLI trust remains unclear because `oh-my-ag` provenance and data flows are not documented here.

Confidence: 81%Severity: 76%
Audit Metadata
Analyzed At
Mar 13, 2026, 09:44 AM
Package URL
pkg:socket/skills-sh/first-fluke%2Foh-my-ag%2Forchestrator%2F@272018c62a18f37956de7cef52d64aa5407d0da9