team-assemble

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose matches agent-team orchestration, and there is no obvious credential theft or third-party exfiltration. Risk comes from broad execution authority, explicit bypassPermissions use, and indirect prompt-injection exposure from reading repo content before allowing subagents to write files and run Bash.

Confidence: 87%Severity: 71%
Audit Metadata
Analyzed At
Apr 17, 2026, 06:07 AM
Package URL
pkg:socket/skills-sh/team-attention%2Fheum-workshop%2Fteam-assemble%2F@000a249ff6ae9d503392fe26b2a688d105b86a6d