sub-agent-orchestrator

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose matches orchestration, but it grants broad autonomous multi-agent execution with Bash/Write and recursively propagates untrusted content between agents without clear safeguards. No malicious install path or explicit exfiltration is present, so this looks like a high-risk orchestration skill rather than confirmed malware.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Apr 10, 2026, 05:28 PM
Package URL
pkg:socket/skills-sh/onewave-ai%2Fclaude-skills%2Fsub-agent-orchestrator%2F@ea221595dde2bdc0a9e4ac5a981a000ed0db0fa0