team-lifecycle-v5

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The analyzed fragment describes a coordinator-centric orchestration of multi-role workers with role-specific specs and subagents. While there is no evident malicious data flow or credential exposure in the fragment, the broad permission surface (shell tool access and background worker autonomy) warrants strict sandboxing, input validation, and access controls. Overall, the design is credible and benign in intent, but operational safeguards are essential to mitigate misuse risk.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 11:07 AM
Package URL
pkg:socket/skills-sh/catlog22%2Fclaude-code-workflow%2Fteam-lifecycle-v5%2F@c6adfe6d2c34795bb27a318a099f43d8c48f9bc8