team-testing
Warn
Audited by Socket on Apr 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s core purpose is coherent, but it operates with very broad autonomous powers and depends on external orchestration components (`maestro`, MCP message bus) whose trust boundaries are only partly verifiable from the skill text. No clear credential theft or malicious exfiltration is present, but the combination of wildcard tools, background agents, repo modification, and partially verified external tooling makes this a medium-to-high risk orchestration skill rather than benign low-risk documentation.
Confidence: 87%Severity: 68%
Audit Metadata