workflow

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill's stated purpose is coherent, and its file access is proportionate, but its entire execution model depends on an `agent-team` CLI whose provenance could not be verified from the supplied evidence. There is no clear credential theft or exfiltration behavior in the skill text, yet the unresolved trust of the required external CLI makes overall security risk high.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Mar 14, 2026, 07:51 AM
Package URL
pkg:socket/skills-sh/JsonLee12138%2Fagent-team%2Fworkflow%2F@e85858714abafb250216c3d5d14a4eb3bcf97a97