team

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly align with its stated purpose as a tmux-based multi-agent orchestrator, and its data flow is local rather than overtly exfiltrative. However, it grants broad execution power, enables persistent autonomous worker sessions, instructs autonomous git commits, and most notably weakens safety controls through `--dangerously-skip-permissions` plus auto-accept trust/bypass behavior. This is not confirmed malware, but it is a high-impact operational skill that should be treated as medium-high risk.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
May 6, 2026, 05:09 PM
Package URL
pkg:socket/skills-sh/Yeachan-Heo%2Foh-my-codex%2Fteam%2F@c99c59466531c46b567469f1d1a98898340c080a