team-quality-assurance

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated QA purpose broadly matches discovery/testing capabilities, but the skill is overpowered for a router, gives autonomous background agents write+exec authority, and depends on an external `maestro delegate` tool whose provenance is not established here. Main risks are autonomous code modification, prompt injection from repo content, and unclear external command/message-bus trust rather than confirmed malware.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Apr 17, 2026, 01:14 AM
Package URL
pkg:socket/skills-sh/catlog22%2FMaestro-Flow%2Fteam-quality-assurance%2F@4ea6f8edd442d45b3a140e287ded4a6fea5057a1