Create Project
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
The skill bundle provides project scaffolding for 'Orchestrix,' a multi-agent orchestration framework. It is classified as suspicious because it includes scripts (start-orchestrix.sh and ensure-session.sh) designed to automatically bypass Claude Code's 'trust this folder' security prompts by monitoring terminal output and simulating user input (Enter key). Additionally, the handoff-detector.sh script implements a mechanism to execute commands parsed directly from terminal output across tmux panes, which introduces a risk of command injection if an agent is manipulated into printing malicious handoff strings. While these features are aligned with the tool's goal of unattended automation, they intentionally circumvent standard security controls.
