team-init

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent for creating local agent teams and shows no external installer or credential-exfiltration path, but it grants spawned agents bypassPermissions and includes offensive-security team modes. The main risk is excessive autonomous capability, not malware or supply-chain abuse.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Mar 13, 2026, 07:11 PM
Package URL
pkg:socket/skills-sh/killvxk%2FTeamSkills%2Fteam-init%2F@9bbf7ad27091ffb23afc33af02c10f60065a8e36