workflow
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill's stated purpose is coherent, and its file access is proportionate, but its entire execution model depends on an `agent-team` CLI whose provenance could not be verified from the supplied evidence. There is no clear credential theft or exfiltration behavior in the skill text, yet the unresolved trust of the required external CLI makes overall security risk high.
Confidence: 86%Severity: 78%
Audit Metadata