go

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The provided skill is a high-level orchestration entrypoint that parses user goals, creates or resumes tracks, writes planning artifacts to disk, and invokes an orchestrator which dispatches additional agents — potentially with elevated capabilities when 'superpower_enhanced' is set. The text itself contains no direct malicious code (no downloads, no hard-coded credentials, no shell execution). However, it presents moderate supply-chain and autonomy risks because it delegates powerful actions to transitive agents by default, lacking explicit consent gates, scope limitations, or enumerated safeguards. If those downstream agents are untrusted or have network/file permissions, they could perform harmful or unexpected actions. Recommend treating this skill as suspicious until the orchestrator and each dispatched agent are reviewed for allowed actions, credential usage, and audit/approval controls.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 08:10 PM
Package URL
pkg:socket/skills-sh/Ibrahim-3d%2Fconductor-orchestrator-superpowers%2Fgo%2F@1ebe4cd64b8d8a6fe05770d0da182c0767c9ef9d