team-assign
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The business purpose is coherent, and most file access fits team assignment workflows, but trust is weakened by a core undocumented executable dependency (team-manager.py) and an unspecified email MCP. Data flows are mostly proportionate, with moderate risk from external notifications and unverifiable execution provenance rather than clear malicious behavior.
Confidence: 82%Severity: 72%
Audit Metadata