workflow-orchestrator

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill/fragment presents a coherent, legitimate workflow orchestrator for multi-agent tasks. It aligns with its stated purpose and generally uses standard, expected sources, sinks, and data flows. The primary security considerations are access control for remote workflow invocation and secure handling of API keys/credentials in real deployments. There is no clear evidence of malicious behavior within the provided fragment, though the remote execution and API exposure patterns warrant careful security controls. Overall risk is moderate (benign with caveats).

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:14 AM
Package URL
pkg:socket/skills-sh/winsorllc%2Fupgraded-carnival%2Fworkflow-orchestrator%2F@9cc975da76f7945b3cd86fe221146c18bc25afed