team-lifecycle-v4

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The overall workflow is coherent for a team-orchestration skill, but its trust boundary is weakened by broad autonomous permissions and an ambiguous external `maestro delegate` dependency whose provenance does not cleanly match a verifiable official same-org tool. No clear credential theft or malicious exfiltration is shown, so this is not confirmed malware, but it is a high-risk skill to run without verifying the exact `maestro` binary and constraining permissions.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Apr 17, 2026, 01:13 AM
Package URL
pkg:socket/skills-sh/catlog22%2FMaestro-Flow%2Fteam-lifecycle-v4%2F@53c483e5bb63b0f6d0f2c709280e44eab22152fd