octopus-architecture

Warn

Audited by Socket on May 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is architecture design, but the skill mandates executing a third-party local orchestrator cloned from GitHub and refuses to operate without it. That is not clearly malicious, yet it materially enlarges install and execution trust, obscures downstream data flows, and makes the skill riskier than a normal design-review guide.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
May 9, 2026, 06:37 AM
Package URL
pkg:socket/skills-sh/nyldn%2Fclaude-octopus%2Foctopus-architecture%2F@c4ff5c1b876f8a36c07ccc1856e96c6634c57a96