agent-queen-coordinator

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The code implements a logically powerful orchestrator (queen-coordinator) that writes authoritative commands and state into a shared coordination memory. It contains no direct signs of classical malware (no network exfiltration, shell access, obfuscation, or hard-coded secrets), but it centralizes control with no visible access control or validation. That design poses a substantial operational and supply-chain risk: a compromised or rogue instance could manipulate or disrupt the swarm (resource starvation, forced directives, persistent state overwrite). Deploy only with strong platform-level authentication, per-key ACLs, validation, rate-limiting, and auditing.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 11:49 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fclaude-flow%2Fagent-queen-coordinator%2F@adb958e344d46126a3d07c0881c427adb282e584