team-level

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This skill is functionally appropriate for orchestrating a team-based level design workflow and does not contain explicit malicious code or exfiltration instructions. However, it grants broad runtime capabilities (Bash, Task, Read, Write/Edit) without specifying sandboxing, path whitelists, or subagent capability restrictions. The greatest risk is transitive: subagents could be used to execute arbitrary commands or access sensitive files if the execution environment permits. Recommended mitigations: limit Read/Write to project design directories, constrain or remove Bash from allowed-tools (or restrict to non-network, read-only operations), and enforce explicit per-step, human-reviewed approvals for any commands touching non-design paths.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 1, 2026, 11:08 PM
Package URL
pkg:socket/skills-sh/Donchitos%2Fclaude-code-game-studios%2Fteam-level%2F@d3e1634b9474dc0fcbc8f95bad98c53b621373b3