team-review

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core purpose is legitimate, but its footprint is broad for a review workflow. Main concerns are wildcard execution/edit permissions, autonomous subagent spawning, and prompt-injection exposure from analyzing untrusted repo content while retaining write/exec access. Supply-chain risk is moderate rather than critical because the referenced CLI appears verifiable, but it is still a third-party dependency outside the skill publisher.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 17, 2026, 01:13 AM
Package URL
pkg:socket/skills-sh/catlog22%2FMaestro-Flow%2Fteam-review%2F@b1d783018d9f4340361ac3077449f1fee6920121