orchestrator

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s overall purpose is plausible, and the referenced CLIs are consistent with developer tooling, but its actual footprint exceeds a pure coordinator role. The main concerns are contradictory READONLY claims, direct command execution, autonomous draft PR creation, and use of untrusted GitHub/Jira content in workflows that can write files and trigger remote actions.

Confidence: 85%Severity: 61%
Audit Metadata
Analyzed At
Mar 16, 2026, 10:06 AM
Package URL
pkg:socket/skills-sh/i9wa4%2Fdotfiles%2Forchestrator%2F@aca134795ebabc5d85a2b6337c22088afa689d22