team-ux-improve
Warn
Audited by Socket on May 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill’s stated UX-improvement purpose is coherent, but its real trust boundary extends into third-party `ccw`/MCP tooling from a different publisher with download-and-execute style distribution and broad execution authority. That makes this skill suspicious rather than clearly malicious: the main risk is supply-chain and autonomous edit/exec exposure, amplified by external-context ingestion and transitive tool trust.
Confidence: 82%Severity: 74%
Audit Metadata