team-ux-improve

Warn

Audited by Socket on May 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s stated UX-improvement purpose is coherent, but its real trust boundary extends into third-party `ccw`/MCP tooling from a different publisher with download-and-execute style distribution and broad execution authority. That makes this skill suspicious rather than clearly malicious: the main risk is supply-chain and autonomous edit/exec exposure, amplified by external-context ingestion and transitive tool trust.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
May 1, 2026, 01:48 PM
Package URL
pkg:socket/skills-sh/catlog22%2Fclaude-code-workflow%2Fteam-ux-improve%2F@2b11fa3f2950a6a2f0cf82da79fb6ec6923ad47f