task-orchestrator

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill’s core behavior is coherent for orchestration, but it grants an AI agent high-impact autonomous capabilities: executing Codex with `--yolo`, consuming untrusted GitHub issue content, self-healing without approval, and pushing code plus creating PRs automatically. The main risks are autonomy abuse, indirect prompt injection, and shell/prompt injection via issue-derived text, not malicious installer provenance.

Confidence: 93%Severity: 82%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:01 PM
Package URL
pkg:socket/skills-sh/jdrhyne%2Fagent-skills%2Ftask-orchestrator%2F@bf43b5ec3007ce47b87d0b8dfa833545e0d1e23f