team-assemble

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill correctly implements orchestration of multi-agent teams to decompose and solve complex tasks. It does not contain obvious hardcoded secrets, external downloads, or direct malicious payloads. However, example use of mode: "bypassPermissions", fully automated lifecycle after a single approval, and verbatim forwarding of teammate outputs create meaningful security risks: privilege escalation, easier data exfiltration of secrets/PII, and potential concealment via TeamDelete. These are design/operational risks rather than confirmed malware. I recommend removing bypassPermissions usage, introducing sanitization and least-privilege guidance, requiring finer-grained human approval for sensitive operations, and ensuring immutable audit logging.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 25, 2026, 02:39 AM
Package URL
pkg:socket/skills-sh/team-attention%2Fworkshop-upstage%2Fteam-assemble%2F@f13001c829b95a3c03a6c322567a4d6f2aa369ce