oma-orchestrator

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's capabilities mostly match its orchestration purpose, but it grants an AI agent broad autonomous control over spawning subprocesses, running verification loops, and acting on untrusted repository content. The main concern is high operational autonomy and prompt-injection exposure, not confirmed credential theft or malware.

Confidence: 83%Severity: 76%
Audit Metadata
Analyzed At
Mar 21, 2026, 09:37 PM
Package URL
pkg:socket/skills-sh/gracefullight%2Fstock-checker%2Foma-orchestrator%2F@89bb417ae19634858f62152783c7d43d2c91d71c