team-executor
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileThe skill's high-level objective of autonomous planning and execution is coherent with its described two-phase approach and supporting tooling. However, the footprint introduces notable security and governance risks due to freely autonomous execution (Phase 2) and reliance on local/scripted steps (Phase 1) that could be manipulated if input is not properly sanitized and if safety nets are not in place. The data flows are generally contained within the project workspace, but possible leakage of sensitive braindump content or cross-skill data access warrants explicit access controls and auditing. Overall, the design is plausible for a teams-orchestration tool but should be treated as SUSPICIOUS until concrete safeguards (kill-switch, input validation, explicit human-in-the-loop checks for risky actions, and strict data handling policies) are documented and implemented.