subagent-driven-development

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is plausible, but it normalizes launching multiple background Claude subprocesses in `bypassPermissions` mode, giving parallel agents broad unsupervised authority. Install provenance is same-org and benign, but the autonomy and permission scope are disproportionate to simple task orchestration.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Mar 21, 2026, 05:56 AM
Package URL
pkg:socket/skills-sh/ArchieIndian%2Fopenclaw-superpowers%2Fsubagent-driven-development%2F@45655661646e2c5847930aff74bfa7d36bbe9a12