community-post

Fail

Audited by Socket on Mar 6, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The orchestrator itself does not contain direct malicious code patterns (no network endpoints, no credential use, no command execution). The highest risk is transitive: it forwards local episode metadata and user inputs to foundation skills without enforced trust boundaries or sanitization, and it writes foundation-supplied content to disk upon approval. Recommend treating invoked foundation skills as untrusted inputs: implement path normalization, output sanitization, least-privilege execution for foundation skills, and logging/auditing of their behavior. With those mitigations, the orchestrator can be used safely; without them, it presents a moderate supply-chain/transitive risk primarily due to potential data exfiltration or malicious content insertion.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 6, 2026, 01:34 AM
Package URL
pkg:socket/skills-sh/kenneth-liao%2Fai-launchpad-marketplace%2Fcommunity-post%2F@73592c61f079994864e3549af4d41b2e443c02a2