orchestrator
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s core purpose matches orchestration, and the referenced CLIs appear to be official developer tools rather than fake payloads. The main risk is scope and autonomy: it empowers the agent to spawn subprocesses, run background AI CLIs, merge/delete branches, and push code with limited approval boundaries, so it is a high-risk automation skill rather than confirmed malware.
Confidence: 84%Severity: 71%
Audit Metadata