subagent-driven-development
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose is plausible, but it normalizes launching multiple background Claude subprocesses in `bypassPermissions` mode, giving parallel agents broad unsupervised authority. Install provenance is same-org and benign, but the autonomy and permission scope are disproportionate to simple task orchestration.
Confidence: 90%Severity: 74%
Audit Metadata