team-update

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose matches the workflow, and there is no installer or obvious credential-harvesting behavior. The main concerns are wildcard tool permissions and prompt-injection exposure from reading untrusted external chat/issues while retaining broad action capability. External actions are approval-gated, which lowers but does not remove the risk.

Confidence: 89%Severity: 66%
Audit Metadata
Analyzed At
Mar 19, 2026, 10:32 PM
Package URL
pkg:socket/skills-sh/jezweb%2Fclaude-skills%2Fteam-update%2F@d999b272e6be0741d90973ac65cc87bbf15f25d1