stitch-orchestrator

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose and Stitch-centric capabilities are mostly aligned, and there is no clear credential harvesting or obvious malicious installer. However, it is a high-authority autonomous orchestrator with broad stitch* + Bash/Write access, delegates into other skills, and fetches remote HTML through an unseen local script using runtime URLs. That footprint is riskier than a simple design helper and merits medium-high security concern, but it is not confirmed malware.

Confidence: 84%Severity: 66%
Audit Metadata
Analyzed At
Mar 26, 2026, 01:34 AM
Package URL
pkg:socket/skills-sh/gabelul%2Fstitch-kit%2Fstitch-orchestrator%2F@79e3dbf8ba4163d47eccb62e8a4a927d0cf4a29c