dev-orchestrator

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core purpose is coherent, and there is no clear credential theft, exfiltration, or third-party installer. However, it imposes unusually forceful workflow control: broad auto-activation, mandatory immediate Bash execution, detached long-running tmux sessions, and hook-based compliance pressure. That makes it higher risk than a normal documentation or routing skill, especially for investigation tasks where untrusted input may trigger execution before review.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Mar 14, 2026, 03:26 PM
Package URL
pkg:socket/skills-sh/rysweet%2Famplihack%2Fdev-orchestrator%2F@7a263ea68b4fa2f9e5585e457ea40261cf0370fe