council

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core debate/orchestration behavior is broadly consistent with the stated purpose, and the Codex/GitHub CLI references look plausibly official. However, the skill requires a custom unverifiable `hoyeon-cli`, grants spawned agents `bypassPermissions`, and mixes untrusted external content ingestion with Bash-capable multi-agent execution. That makes the overall footprint high risk for a deliberation skill, even without clear evidence of outright malware.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Apr 8, 2026, 11:03 AM
Package URL
pkg:socket/skills-sh/team-attention%2Fhoyeon%2Fcouncil%2F@353a69af496ce60196e2ed4b55bae6eb5116a838