ensemble-team

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's core purpose and file-creation behavior are mostly coherent and there is no clear credential theft, malicious exfiltration, or suspicious installer path. However, it combines untrusted WebSearch-derived content with persistent agent-profile generation and recommends broad Bash(*) permissions, which meaningfully increases prompt-injection and autonomy risk for a skill whose main job is scaffolding team configuration.

Confidence: 86%Severity: 52%
Audit Metadata
Analyzed At
Mar 25, 2026, 04:22 PM
Package URL
pkg:socket/skills-sh/jwilger%2Fagent-skills%2Fensemble-team%2F@15053523d9da04c245bc4e06faaa7d22037b1c63