orchestrator

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's core orchestration behavior matches its stated purpose, and there is no clear malicious installer or credential-exfiltration path. However, it grants powerful autonomous background execution to child agents via tmux and --dangerously-skip-permissions, while feeding them repo/spec content that could contain prompt-injection instructions. This is a high operational security risk even without confirmed malware.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Apr 3, 2026, 11:03 AM
Package URL
pkg:socket/skills-sh/harivansh-afk%2Fclaude-code-vertical%2Forchestrator%2F@9d01b3abdc21060bc7d2ebb021486ec730935025