team-tech-debt

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align with tech-debt remediation, but it grants broad autonomous write/exec powers, processes untrusted repository content, and depends on partially unverifiable orchestration components. No clear credential theft or exfiltration path is shown, so this is not malicious, but it is a medium-risk agent skill.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
Apr 17, 2026, 01:14 AM
Package URL
pkg:socket/skills-sh/catlog22%2FMaestro-Flow%2Fteam-tech-debt%2F@f67f041af0d1d7a81ac996492fbf02422550581b