octopus-architecture
Warn
Audited by Socket on May 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is architecture design, but the skill mandates executing a third-party local orchestrator cloned from GitHub and refuses to operate without it. That is not clearly malicious, yet it materially enlarges install and execution trust, obscures downstream data flows, and makes the skill riskier than a normal design-review guide.
Confidence: 85%Severity: 74%
Audit Metadata