agent-sync-coordinator

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This skill/specification matches its stated purpose and uses legitimate GitHub and orchestration operations. There is no explicit malicious code, C2, or obfuscation in the provided fragment. However, the workflow exercises high-impact capabilities (reading arbitrary workspace files and writing to repositories via API/gh CLI). The primary security concern is misuse or misconfiguration: accidental exfiltration of secrets, unauthorized repository modifications, or improper target resolution via template placeholders. Treat as high-privilege tooling that requires strict credential scoping, input allowlisting, audit logging, and operational controls before deployment.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 10:38 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fclaude-flow%2Fagent-sync-coordinator%2F@b7ddf3d9a5e216b8a77bddeb0a30713df62d4fc9