parallel-claudes

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The orchestrator is functional and useful in trusted, isolated environments, but it intentionally removes interactive safety checks and automates high-privilege actions (autonomous headless agents committing and pushing code). There is no explicit malicious code in the document, but the workflow materially increases supply-chain and code-integrity risks because it enables automated exfiltration or injection if a subagent or prompt is malicious or compromised. Recommended precautions: avoid --dangerously-skip-permissions unless in an isolated throwaway environment; require manual review of all commits before pushing/merging; sandbox or disable repository credentials for subagent runs; verify installer scripts before execution; and prefer interactive/manual merges with human inspection.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:55 AM
Package URL
pkg:socket/skills-sh/joyco-studio%2Fskills%2Fparallel-claudes%2F@aaf302aac7f0a77fded6a66bc0f904bb4b4c13c1