task-orchestrator

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The code fragment describes a sophisticated autonomous orchestration framework that uses Codex-driven commands within tmux sessions, per-task git worktrees, and GitHub interactions to manage tasks. While powerful for large projects, it introduces meaningful supply-chain and runtime risks due to autonomous code changes, prompt-driven execution, self-healing actions, and credential exposure pathways. The overall posture should be considered SUSPICIOUS-to-REQUIRING_GOVERNANCE until strong human-in-the-loop controls, sandboxing, prompt validation, and audit logging are implemented to mitigate risk.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 05:09 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Ftask-orchestrator%2F@bd21bc22039ab72cae8b5e108b55297a68e911ac