dev-orchestrator
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s core purpose is coherent, and there is no clear credential theft, exfiltration, or third-party installer. However, it imposes unusually forceful workflow control: broad auto-activation, mandatory immediate Bash execution, detached long-running tmux sessions, and hook-based compliance pressure. That makes it higher risk than a normal documentation or routing skill, especially for investigation tasks where untrusted input may trigger execution before review.
Confidence: 84%Severity: 61%
Audit Metadata