Back to skill
Skillv3.0.0

VirusTotal security

Orchestrix Guide · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 29, 2026, 5:52 AM
Hash
dd51a6c4be97b83e3db046b626f2498887fc6162b59287e9b5d689ea40622870
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: orchestrix-guide Version: 3.0.0 The skill bundle defines a complex multi-agent orchestration workflow that automates 'Claude Code' via tmux. It explicitly mandates the use of the '--dangerously-skip-permissions' flag, which bypasses critical security prompts for the AI agent. Furthermore, the instructions in SKILL.md rely on executing multiple external shell scripts (e.g., start-orchestrix.sh, monitor-agent.sh, and handoff-detector.sh) located in a hidden '.orchestrix-core' directory that are not provided in the bundle, making their actual behavior unverifiable. While these capabilities are plausibly for the stated purpose of automated development, the combination of high-privilege execution and opaque external dependencies poses a significant security risk.
External report
View on VirusTotal