subagents-orchestration-guide

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent as an orchestration guide and shows no third-party install or credential-harvesting behavior, but it grants broad autonomous write/fix/commit authority and mixes WebSearch-derived content with executable workflows. The main risk is agent autonomy and indirect prompt injection, not malware or supply-chain compromise.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Mar 23, 2026, 10:48 AM
Package URL
pkg:socket/skills-sh/shinpr%2Fai-coding-project-boilerplate%2Fsubagents-orchestration-guide%2F@2e7333fad394ef8ff7fe4c9b83f4437ecfc00433